Upgrade to Pro — share decks privately, control downloads, hide ads and more …

SQL Injection〈期末報告〉

Avatar for eric wang eric wang
June 07, 2013
200

SQL Injection〈期末報告〉

2013/06/10 , 資料庫期末報告@F308

Avatar for eric wang

eric wang

June 07, 2013
Tweet

Transcript

  1. About Me 王仁宏(Blue Wang) 「駭」你好 資安社團 Founder Hacks in Taiwan

    Conference2012台灣駭客年會 101年度資安系列競賽 對於資訊安全有高度興趣, 卻沒有相關天份的一個人。
  2. XD

  3. DELETE – 從Table 中刪除 data INSERT INTO – 插入新資料 到Table

    SELECT – 查詢Table內data UPDATE – 更新 Table內data DML
  4. "SELECT Username FROM Users WHERE Username = ' " &

    strUsername & " ' AND Password = ' " & strPassword & " ' "
  5. 在登入網頁輸入( ' or 1=1-- ) 則傳到資料庫中的字串會變成 User Input Web ''SELECT

    Username FROM Users WHERE Username = ' " & strUsername & " ' AND Password = ' " & strPassword & " ' "
  6. 見證奇蹟的時刻 ''SELECT Username FROM Users WHERE Username = ' '

    or 1=1-- ' AND Password = ' ' or 1=1-- ' " ''SELECT Username FROM Users WHERE Username = ' " & strUsername & " ' AND Password = ' " & strPassword & " ' " User Input:( ' or 1=1-- )