<?php
$_GET['id'] = '1"; DROP TABLE users; -- ';
echo 'GOOD';
// obvious sql injection:
// mysql_query('SELECT * FROM users WHERE id = ' . $_GET['id']);
// ...
} else {
echo 'BAD';
}
PD9waHAKCiRfR0VUWydpZCddID0gJzEiOyBEUk9QIFRBQkxFIHVzZXJzOyAtLSAnOwoKJHZhbGlkID0gYXJyYXkoMSwgMiwgMyk7CgppZiAoaW5fYXJyYXkoJF9HRVRbJ2lkJ10sICR2YWxpZCkpIHsKCWVjaG8gJ0dPT0QnOwoJCgkvLyBvYnZpb3VzIHNxbCBpbmplY3Rpb246CgkvLyBteXNxbF9xdWVyeSgnU0VMRUNUICogRlJPTSB1c2VycyBXSEVSRSBpZCA9ICcgLiAkX0dFVFsnaWQnXSk7CgkvLyAuLi4KfSBlbHNlIHsKCWVjaG8gJ0JBRCc7Cn0=