How to do it...

  1. From the OWASP Mutilliae II menu, select Login by navigating to OWASP 2013 | A1-Injection (SQL) | SQLi – Bypass Authentication | Login:
  1. At the Login screen, place invalid credentials into the username and password text boxes. For example, username is tester and password is tester. Before clicking the Login button, let's turn on Proxy | Interceptor.
  2. Switch to the Burp Proxy | Intercept tab. Turn the Interceptor on by toggling to Intercept is on.
  1. While Proxy | Interceptor has the request paused, insert the new payload of ' or 1=1--<space> within the username parameter and click the Login button:
  1. Click the Forward button. ...

Get Burp Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.