QA Bug Playground

SQL Injection Playground

🇻🇳 Sân chơi chèn lệnh SQL

Login

🇻🇳 Đăng nhập
💡 Hint: Both fields are dropped straight into the SQL string. Username ' OR '1'='1' -- with any password comments out the password check entirely and logs you in as the first row in the table (admin).
🇻🇳 Cả hai trường đều bị chèn thẳng vào chuỗi SQL. Username ' OR '1'='1' -- với bất kỳ password nào sẽ comment-out toàn bộ điều kiện kiểm tra mật khẩu và đăng nhập bạn thành dòng đầu tiên trong bảng (admin).

Product search

🇻🇳 Tìm kiếm sản phẩm
💡 Hint: This LIKE query is concatenated too. Because it returns full rows, a UNION with a matching column count (' UNION SELECT id, username, password, 0 FROM users -- ) dumps the users table straight into the product grid. Also note the box itself: the last search term is echoed back into the value="..." attribute unescaped, so a payload like "><script>alert(1)</script> breaks out of the attribute too (reflected XSS, separate from the SQLi).
🇻🇳 Câu lệnh LIKE này cũng bị nối chuỗi. Vì nó trả về nguyên hàng dữ liệu, một UNION với đúng số cột (' UNION SELECT id, username, password, 0 FROM users -- ) sẽ trút toàn bộ bảng users thẳng vào lưới sản phẩm. Ngoài ra, chính ô tìm kiếm cũng có vấn đề: từ khóa tìm kiếm gần nhất được hiển thị lại vào thuộc tính value="..." mà không escape, nên một payload như "><script>alert(1)</script> cũng thoát được khỏi thuộc tính đó (reflected XSS, tách biệt với lỗi SQLi).

Username availability check (blind SQL injection)

🇻🇳 Kiểm tra username còn trống (blind SQL injection)

💡 Hint: This endpoint never shows you any data back -- just "available" or "taken" -- which is exactly the shape of a blind SQL injection. It's built the same vulnerable way: SELECT 1 FROM users WHERE username = '${u}'. Try admin' AND '1'='1 (taken) vs admin' AND '1'='2 (available) to prove the query is executing your condition, then a senior tester would automate character-by-character extraction with something like admin' AND substr(password,1,1)='S. A quick functional pass usually stops at "does search work," and never notices this quieter endpoint exists.
🇻🇳 Endpoint này không bao giờ trả dữ liệu về cho bạn -- chỉ "available" hoặc "taken" -- đúng chính xác hình dạng của một lỗi blind SQL injection. Nó được dựng theo cùng kiểu lỗi: SELECT 1 FROM users WHERE username = '${u}'. Thử admin' AND '1'='1 (taken) so với admin' AND '1'='2 (available) để chứng minh điều kiện của bạn thực sự được thực thi, rồi một senior tester sẽ tự động hóa việc trích xuất từng ký tự bằng thứ như admin' AND substr(password,1,1)='S. Một lượt test chức năng nhanh thường chỉ dừng lại ở "tìm kiếm có chạy không" và không bao giờ để ý endpoint âm thầm này tồn tại.