214, 2/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ewqqw
   SQL injection ±âº»

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=236 [º¹»ç]


<!--Ignore this.-->
<html><body><form action='sqli_nth.php' method='get'><table><tr><td>id</td><td><input type='text' name='id'></td></tr><tr><td>pw</td><td><input type='text' name='pw'></td></tr><tr><td><input type='submit'></td></tr></table></form><hr></body></html>

<?php
  require 'config.php';//Ignore this.
  require 'flag.php';//Ignore this.

  $mysqli = mysqli_connect('localhost', 'newbiesqli2', 'newbiesqli_2', 'newbiesqli2') or die('Error : Please let dohyeokkim know this happening.');//Ignore this.

  $q = "select * from sqli2 where id='{$_GET[id]}' and pw='{$_GET[pw]}'";//query
    
  if(preg_match('/admin|x|b|conv|id|pw|\(/i', $_GET[id])) exit("No!");
  if(preg_match('/admin|x|b|conv|id|pw|\(/i', $_GET[pw])) exit("No!");

  echo $q;//This will show you query.
  echo '<hr>';

  $result = mysqli_fetch_array(mysqli_query($mysqli, $q));//Ignore this.

  //result
  if($result[id]){
    echo 'Succeed in login.<br>Hi! '.$result[id].'<br><br>';

    if($result[id] == 'admin')
      solve('sqli_nth');//Good!
  }
  else
    echo 'Failed to login.';

  echo '<hr>';

  highlight_file(__File__);//This will show you query.
?>

'or '1'='1 °°Àº °ÍµéÀº ¾ÈµÇ³×¿ä......

  Hit : 3130     Date : 2017/03/24 11:01



    
194   À¥ÇØÅ·¿¡ ÇÊ¿äÇÑ ¾ð¾î[3]     yunpung1234
08/17 3663
193   Webhacking.kr ¹®Á¦¸¦ Ç®´Ù°¡..     alstnsms67
08/02 2678
192   APMSETUP7À» ¼³Ä¡ÇÏ·Á°íÇϴµ¥..     0429njy
07/22 2390
191   À¥ÇØÅ·ÇÏ°í½Í¾î¼­ ¹è¿ì°íÀִµ¥ htmlÇÏ°í css ű׳ª»ö»óµîµî..ÀÌ·±°Å±îÁö ¹è¿ïÇÊ¿ä°¡ÀÖ³ª¿ä?;;[8]     ykk98433
06/29 4028
190   ¹ö±× ¹Ù¿îƼ ±âÃÊ     wwwlk
06/27 2782
  SQL injection ±âº»     ewqqw
03/24 3129
188   cookie °ü·Ã[1]     ewqqw
03/23 2666
187   Post Method[2]     ewqqw
03/16 2516
186   POST METHOD     ewqqw
03/13 2380
185   get method ¿¡ °üÇÑ Áú¹®[1]     ewqqw
03/13 2735
184   [À¥Áú¹®] »çÀÌÆ® ¼Ò½º¸¦ Åë°·Î °®°í¿À´Â ÅøÀÌ ÀÖ³ª¿ä?[2]     helpwizet
03/08 5207
183   False Injection¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[3]     dudtntdud
01/18 2610
182   ¸ÞÀÏ ÇØÅ·¿¡ ´ëÇؼ­ ¹®ÀÇ ÇÕ´Ï´Ù[5]     wqw3
12/16 5036
181   À¥ÇØÅ· ¹è¿ï·Á°í ÇÕ´Ï´Ù[2]     aktrg1234
11/09 3168
180   °Ô½Ã¹° ºñ¹Ð¹øÈ£ ¿ìȸ     qkrrmsgP
11/08 4120
179   Ä®¸®¸®´ª½º À¥ Ãë¾àÁ¡ Á¡°Ë ½ºÄ³³Ê Áú¹®..     duwkakstp1
08/21 4073
178   Å©·¡Å· ÇØÁֽǺР±¸ÇØ¿ä (ºÒ¹ýx) »ç·Êµå¸³´Ï´Ù.     mss0812
06/22 3184
177   ¹ÙµÏÀÌ ¿Ãºä¾î Á¦ÀÛÀÚ ¸ð½Ê´Ï´Ù     killerkor
05/25 3040
176   HTTP Çì´õ[1]     chaneyoon
04/30 2786
175   ÄíÅ°¹®ÀÇ[3]     sm8303
04/21 2803
[1] 2 [3][4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org