Get the App
SLTechnology News&Howtos  ›  Internet Technology  › 

How does the website prevent SQL injection

Shulou Source: shulou.com Published: 2022-06-01 10:15:10 10月05日 Update

In this issue, Xiaobian will bring you about how to prevent SQL injection on the website. The article is rich in content and analyzed and described from a professional perspective. After reading this article, I hope you can gain something.

We know that most websites use MYSQL database, when the website appears such as the following form, the form needs to enter data into the database, but if someone is very familiar with MYSQL statements, and knows the name of the form (and column name), the owner of the website does not pay attention to these times, then he can easily inject.

For example, this sentence in my page is an example of how easy it is to receive attacks.

For ease of explanation, let's simplify it:

mysqli_query($conn,"insert into XXXX(pick_name) values ('$_POST[pickName]')");

We know that it is to pass the pickName parameter passed from the form to the pick_name column in XXXX in the database.

But if the User knows our form name, it enters: value');Delect from XXXX;--

Thus, the entire sentence becomes:

mysqli_query($conn,"insert into XXXX(pick_name) values ('value');Delect from XXXX;--')");

Congratulations, XXXX is gone.

So if I dare to type this, I will also hack my website.

Another example is this horrible example in the PHP manual (MSSQL):

Attack the operating system of the host on which the database resides (MSSQL Server)

Tags: Websites forms statements names data that is databases attacks variables hosts examples content parameters characters strings time users analysis input preprocessing Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info OPPO Reno Shulou Information Apple Xiaomi