Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

How does the website prevent SQL injection

2025-02-25 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Internet Technology >

Share

Shulou(Shulou.com)06/01 Report--

In this issue, Xiaobian will bring you about how to prevent SQL injection on the website. The article is rich in content and analyzed and described from a professional perspective. After reading this article, I hope you can gain something.

We know that most websites use MYSQL database, when the website appears such as the following form, the form needs to enter data into the database, but if someone is very familiar with MYSQL statements, and knows the name of the form (and column name), the owner of the website does not pay attention to these times, then he can easily inject.

For example, this sentence in my page is an example of how easy it is to receive attacks.

For ease of explanation, let's simplify it:

mysqli_query($conn,"insert into XXXX(pick_name) values ('$_POST[pickName]')");

We know that it is to pass the pickName parameter passed from the form to the pick_name column in XXXX in the database.

But if the User knows our form name, it enters: value');Delect from XXXX;--

Thus, the entire sentence becomes:

mysqli_query($conn,"insert into XXXX(pick_name) values ('value');Delect from XXXX;--')");

Congratulations, XXXX is gone.

So if I dare to type this, I will also hack my website.

Another example is this horrible example in the PHP manual (MSSQL):

Attack the operating system of the host on which the database resides (MSSQL Server)

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Internet Technology

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report