当前位置:网站首页>SQL injection Foundation
SQL injection Foundation
2022-07-06 18:35:00 【Aspirin. two thousand and two】
SQL Inject the foundation
Access Inject +Access Offset Injection
Digital SQL Inject
Pure number , example :id=1
Search type SQL Inject
Directly inject... Into the search box
Character SQL Inject
The argument is a string ,id=shangpin1
Be careful : Injection is based on the database, not the scripting language
SQL The principle of injection generation is analyzed in detail
Controllable variable , Bring in the database query , The variable does not exist or the filtering is not rigorous
The following existence injection is
www.abc.com/index.php?id=10
www.abc.com/?id=10
www.abc.com/?id=10&x=1
www.abc.com/index.php
All possible , however www.abc.com/index.php May be post Inject
Parameters x There is injection , Which of the following injection tests is correct
www.abc.com/news.php?y=1 and 1=1&x=2
www.abc.com/news.php?y=1&x=1 and 1=1
www.abc.com/news.php?y=1 and 1=1&x=2 and 1=1
www.abc.com/news.php?xx=1 and 1=1&xxx=2 and 1=1
b and c correct
because x Injection of being , So the injection statement should be given to x Back
Various databases
Access,MySQL,msSQL,MongoDB,postgresql,sqlite,Oracle,sybase Such as the database , except access The composition of other databases is roughly the same
Access
Table name
Name
data
MySQL,msSQL etc.
Database name A
Table name
Name
data
Database name
Table name
Name
data
No matter what database , It needs to be injected step by step , Data cannot be injected directly
边栏推荐
- Specify flume introduction, installation and configuration
- Stm32+hc05 serial port Bluetooth design simple Bluetooth speaker
- Self supervised heterogeneous graph neural network with CO comparative learning
- Some understandings of tree LSTM and DGL code implementation
- Use cpolar to build a business website (1)
- 2022 Summer Project Training (II)
- Docker installation redis
- 第三季百度网盘AI大赛盛夏来袭,寻找热爱AI的你!
- [swoole series 2.1] run the swoole first
- AFNetworking框架_上传文件或图像server
猜你喜欢

重磅硬核 | 一文聊透对象在 JVM 中的内存布局,以及内存对齐和压缩指针的原理及应用

巨杉数据库首批入选金融信创解决方案!

Top command details

10、 Process management

【Swoole系列2.1】先把Swoole跑起来

CSRF漏洞分析

Why does wechat use SQLite to save chat records?

Docker installation redis

Numerical analysis: least squares and ridge regression (pytoch Implementation)

44所高校入选!分布式智能计算项目名单公示
随机推荐
巨杉数据库首批入选金融信创解决方案!
【剑指 Offer】 60. n个骰子的点数
Interesting - questions about undefined
华为0基金会——图片整理
HMS core machine learning service creates a new "sound" state of simultaneous interpreting translation, and AI makes international exchanges smoother
【中山大学】考研初试复试资料分享
Easy to use PDF to SVG program
C language college laboratory reservation registration system
使用cpolar建立一个商业网站(1)
Stm32+mfrc522 completes IC card number reading, password modification, data reading and writing
转载:基于深度学习的工业品组件缺陷检测技术
复现Thinkphp 2.x 任意代码执行漏洞
First, look at K, an ugly number
Windows连接Linux上安装的Redis
Docker installation redis
[.Net core] solution to error reporting due to too long request length
Xu Xiang's wife Ying Ying responded to the "stock review": she wrote it!
Transport layer congestion control - slow start and congestion avoidance, fast retransmission, fast recovery
celery最佳实践
Top command details