Burp Suite User Forum

Create new post

Lab: SQL injection attack, querying the database type and version on MySQL and Microsoft

Abner | Last updated: Sep 18, 2020 02:47PM UTC

The given solution ends with a # for comment but this doesn't seem to work. A double dash followed by a space (URL encoded ofc) works fine.

Ben, PortSwigger Agent | Last updated: Sep 21, 2020 08:38AM UTC

Hi, Are you supplying the payload using Burp or are you trying to enter it directly into the address bar of your browser? If you are trying to enter it directly then you need to think about encoding special characters.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.