> For the complete documentation index, see [llms.txt](https://thamizhiniyancs.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thamizhiniyancs.gitbook.io/writeups/overthewire/natas/level-13-level-14.md).

# Level 13 - Level 14

```
Username: natas14
Password: qPazSJBmrmU7UQJv17MHk1PGC4DxZMEP
URL:      http://natas14.natas.labs.overthewire.org
```

## Overview

This time a login form, with a link to the source code.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FtddEv6bfG0oU9QF7O22y%2Fimage.png?alt=media&amp;token=7ccabae9-3143-4769-99e0-25ca0818329f" alt=""><figcaption></figcaption></figure>

***

## Source Code Analysis

Let's take a look at the source code.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2F9b4VoYhAjdYsYOszTGFW%2Fimage.png?alt=media&amp;token=3426ada3-d4b3-496a-9f88-c9390b246645" alt=""><figcaption></figcaption></figure>

By just viewing the source code, we can find that its vulnerable to SQL Injection, since the parameters are directly substituted in the SQL query.&#x20;

We can bypass the login by using a simple payload: `" OR 1 = 1 -- -`, and we get the password for the next level.

<div><figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FAdfB156E4gGRqEhwrJ7r%2Fimage.png?alt=media&amp;token=20c84c0d-8de0-4e5d-9297-e89747339cdc" alt="" width="477"><figcaption></figcaption></figure> <figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2Fge5zWNVHZ1MZg7l6TFXH%2Fimage.png?alt=media&amp;token=258e96d7-b20d-4b43-bc44-4b86b9db3c41" alt="" width="470"><figcaption></figcaption></figure></div>
