当前位置:网站首页>SQL injection
SQL injection
2022-06-26 12:23:00 【weixin_ forty-three million four hundred and forty-six thousand】
sql Inject : Appears where the input interacts with the database ; It usually exists on the login page 、 Find pages or add pages where users can find or modify data .
SQL Injection methods can be roughly divided into two categories : Character and number
sql Injection judgment : Construct where you can type sql sentence
Enter single quotes - The quotation mark of the error report is wrong - Digital injection
Enter single quotes - Report errors 1(id Value ) And single quotes - Character injection
and: Both are true
or: An establishment is an establishment
test
1、 First, judge whether there is an injection point ,
Judgment method :
(1) You can enter single quotation marks ’ To test , If the page returns an error , There is Sql Inject
(2)id=1 and 1=1( The page is running normally )、id=1 and 1=2( Page running error )( Digital ) Return to different interfaces , There is sql Inject
(3)id=1 'and ‘1’='1、id=1 'and ‘1’='2( Character ) Return to different interfaces , There is sql Inject
Judge according to the display bit sql Injection type :
(1) Joint injection query : There must be a display bit on the page
(2) Blind annotation based on Boolean : That is, the injection of true or false conditions can be judged according to the returned page ; The page only returns True and False Two types of pages
(3) Based on error reporting injection : That is, the page will return an error message , Or return the result of the injected statement directly to the page ;
(4) Time based delay Injection : That is, no information can be judged based on the content returned from the page , Use conditional statement to check whether time delay statement is executed ( That is, whether the page return time increases ) To judge ;
for example :’ and if(ascii(substr(database(),1,1))=115,1,sleep(5))–+
边栏推荐
- 菜鸟实战UML——活动图
- I want to know whether flush is a stock market? Is online account opening safe?
- Scala-day05-set
- 24 database interview questions that must be mastered!
- Vscode solves the problem of Chinese garbled code
- 2022 China smart bathroom cabinet Market Research and investment Competitiveness Analysis Report
- Change calico network mode to host GW
- Omni channel member link - tmall member link 3: preparation of member operation content
- Statistical genetics: Chapter 2, the concept of statistical analysis
- dried food! Yiwen will show you SD card, TF card and SIM card!
猜你喜欢
HUST網絡攻防實踐|6_物聯網設備固件安全實驗|實驗二 基於 MPU 的物聯網設備攻擊緩解技術
Flannel's host GW and calico
Statistical genetics: Chapter 1, basic concepts of genome
Scala-day06- pattern matching - Generic
Scala problem solving the problem of slow SBT Download
11、 Box styles and user interface
"Pinduoduo and short video speed version", how can I roast!
ctfshow web入门 命令执行web75-77
HUST网络攻防实践|6_物联网设备固件安全实验|实验二 基于 MPU 的物联网设备攻击缓解技术
How to calculate flops and params in deep learning
随机推荐
Matlab programming example: how to count the number of elements in a cell array
Mqtt disconnect and reconnect
2022 edition of investment analysis and "fourteenth five year plan" development prospect forecast report of China's switchgear industry
证券账户可以开通 开户安全吗
Cross platform members get through the two channels of brand Ren Du
Report on in-depth analysis and investment strategy recommendations for China's petroleum coke industry (2022 Edition)
Spark-day03-core programming RDD operator
How can we reach members more effectively?
"Pinduoduo and short video speed version", how can I roast!
Statistical genetics: Chapter 1, basic concepts of genome
Analysis report on dynamic research and investment planning suggestions of China's laser medical market in 2022
Statistical genetics: Chapter 2, the concept of statistical analysis
What determines the rent
Investment planning and forecast report on the future direction of China's smart agriculture during the 14th five year plan (2022)
Build Pikachu shooting range and introduction
Refined operation, extending the full life cycle value LTV
Using the methods in the repository to solve practical problems
2021 q3-q4 investigation report on the use status of kotlin multiplatform
[graduation season · advanced technology Er] I remember the year after graduation
China Medical Grade hydrogel market supply and demand research and prospect analysis report 2022 Edition