' OR '1'='1' --SELECT id, username, role
FROM users
WHERE username = '' OR 1=1 -- '1adminadmin
2aliceuser
3bobuser
DEFENSE AVAILABLESwitch to a parameterized query and the attack stops.
0 ROWSMeridian Holdings · after hours
Every system has a door somebody forgot to lock.
You find them. A real database is on the other side — no simulation, no safety net but the sandbox. Pull three cases. Then learn how they should have stopped you.
' OR '1'='1' --SELECT id, username, role
FROM users
WHERE username = '' OR 1=1 -- '1adminadmin
2aliceuser
3bobuser
DEFENSE AVAILABLESwitch to a parameterized query and the attack stops.
0 ROWSThe five-move heist
Neo names the mark and the take — never the method.
Case the target. Find where your input actually lands.
Type into the form, watch the live query your input builds, then run it.
The take and your score. Nobody stopped you — that is the point.
The vulnerable code beside the fix that closes it. This is defence.
Three cases · one path
8 objectives across three escalating cases. Each run gets a freshly seeded local database.

Starter / 3 objectives
A noisy storefront, an authentication path, and a live query that gives away the flaw.
Auth Bypass · Schema Discovery · Union ExtractionEnter case
Intermediate / 3 objectives
The result disappears. Timing, error behavior, and careful questions reveal what remains.
Blind Boolean · Blind Timing · Error-BasedEnter case
Advanced / 2 objectives
Filters guard the obvious route. Learn why keyword blocking never replaces a real boundary.
WAF Bypass · Stacked QueriesEnter caseReal database · safe playground
Every case runs against SQLite in your browser. The target is isolated, seeded fresh, and resettable at any time.
No real target. No external system receives your payload.
// Input is inserted into source
const q = "SELECT id, username, role
FROM users WHERE username = '" + input + "'";USER INPUT' OR 1=1 --The value escapes the string and rewrites the logic.
// Structure and value stay separate
const q = "SELECT id, username, role
FROM users WHERE username = ?";
db.execute(q, [input]);PARAMETER BOUND, NOT EXECUTED["' OR 1=1 --"]The input remains data. Query structure cannot change.
Submit the injected value.
See rows the user should not get.
Use the parameterized query.
Submit the same exact input.
Only intended data is returned.
Operator support
Everything is isolated, resettable, and made for learning. Clear the questions before your first operation.
Read every answer Neo givesYes. Every job targets only the sandboxed SQLite database in your browser. The practice payload never reaches a real system; site delivery and optional account sync are separate from the target.
No. It runs in a modern browser. The SQLite engine loads on demand the first time you need it — no account needed, no downloads, no setup.
It helps. The game assumes you can read a SELECT and roughly follow a WHERE clause. It teaches you injection — not SQL from zero.
We teach how injection works so you can recognise it and close it — every job ends with the fix, not the break-in. Use it only on systems you own or are allowed to test.
Neo · “Three cases. You keep what you learn — Meridian keeps the bill.”