Sql Injection Challenge 5 Security Shepherd
The most famous hurdle in Challenge 5 is the . If you try admin' UNION SELECT null, null, flag FROM challenge5 -- , the server returns "Malformed Input" or "Hacking Attempt Detected."
Or more cleanly:
Username: admin'' Password: ' OR ''='