How to log in without a password
As we all know, for most applications in Cramp S mode, accounts and passwords are needed to confirm the identity of the client to ensure the security of the server (mainly the security of the database).
For the client authentication mode, the user is generally asked to enter the account name and password first, and there is no corresponding record in the search database; if so, the user of the client is empowered to carry out related operations; if there is no record, the user of the client is not empowered to enter the more inner application. Knowing this, we can tamper with the input of accounts and passwords, such as "& &" (logic and) when looking up accounts and matching passwords, and we can add passwords like "|" (logical OR) and ("1 password 1") to the password content. When searching, the database language looks up the user account name and the password is equal to the corresponding password, or when "1 password 1" is used. Go to a page on the server. Since 1 must be equal to 1, what is useful here is | | or operation, you can definitely go to the next page, so you can log in to some important pages without knowing the password.