Upgrade to Pro — share decks privately, control downloads, hide ads and more …

SQL Injection〈期末報告〉

eric wang
June 07, 2013
180

SQL Injection〈期末報告〉

2013/06/10 , 資料庫期末報告@F308

eric wang

June 07, 2013
Tweet

Transcript

  1. About Me 王仁宏(Blue Wang) 「駭」你好 資安社團 Founder Hacks in Taiwan

    Conference2012台灣駭客年會 101年度資安系列競賽 對於資訊安全有高度興趣, 卻沒有相關天份的一個人。
  2. XD

  3. DELETE – 從Table 中刪除 data INSERT INTO – 插入新資料 到Table

    SELECT – 查詢Table內data UPDATE – 更新 Table內data DML
  4. "SELECT Username FROM Users WHERE Username = ' " &

    strUsername & " ' AND Password = ' " & strPassword & " ' "
  5. 在登入網頁輸入( ' or 1=1-- ) 則傳到資料庫中的字串會變成 User Input Web ''SELECT

    Username FROM Users WHERE Username = ' " & strUsername & " ' AND Password = ' " & strPassword & " ' "
  6. 見證奇蹟的時刻 ''SELECT Username FROM Users WHERE Username = ' '

    or 1=1-- ' AND Password = ' ' or 1=1-- ' " ''SELECT Username FROM Users WHERE Username = ' " & strUsername & " ' AND Password = ' " & strPassword & " ' " User Input:( ' or 1=1-- )