214, 5/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kmc8724
   SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=151 [º¹»ç]


ÇöÀç ½Ç½ÀÁß¿¡ Àִµ¥
replace(º¯¼ö¸í,"'","")

½Ì±Û ÄõÅÍ -> NULL·Î º¯°æÇϴµî
Ư¼ö¹®ÀÚ¸¦ ÀüºÎ NULL·Î º¯°æÇØ ÁÖ¾ú½À´Ï´Ù.

¹°·Ð ÆÄÀÏÀº aspÀ̱¸¿ä.


ÀÌ »óȲÀ» ¿ìȸÇϰųª ¶Õ´Â ¹æ¹ýÀÌ ¹¹°¡ÀÖ½À´Ï±î?
¾Ë·ÁÁÖ¼¼¿ä

  Hit : 4714     Date : 2013/07/03 03:15



    
rubiya ½Ì±ÛÄõÅÍ ÇѱÛÀÚ¸¦ ġȯÇÒ¶§´Â replace¸¦ ¿ìȸÇÒ¼ö´Â ¾øÁö¸¸ ÀԷ¹޴°÷À» ½Ì±ÛÄõÅÍ·Î ¹­Áö ¾Ê¾Ò´Ù¸é °ø¹é¹®ÀÚ(%20)¸¦ »ç¿ëÇؼ­

select * from table where no=1 ¿¡´Ù°¡

select * from table where no=1 union select ...

ÀÌ·±½ÄÀ¸·Î ¿øÇÏ´Â Äõ¸®¸¦ µ¡ºÙÀÏ ¼ö ÀÖ½À´Ï´Ù.

½Ì±ÛÄõÅÍ ÀÚü¸¦ ÇÊÅ͸µÇÒ°æ¿ì¿¡´Â ±× ¿Ü¿¡´Â °ø°ÝÀÌ ºÒ°¡´ÉÇÑ°É·Î ¾Ë°íÀÖ½À´Ï´Ù.
2013/07/04  
kmc8724 rubiya / ·çºñ¾ß´Ô ¸ÕÀú ¼ÒÁßÇÑ ´äº¯ °¨»çµå¸³´Ï´Ù(_ _) °øºÎ°¡ ‰ç½À´Ï´Ù.
* ÀÌ·±°Íµµ replace·Î ¸·Àº»óÅÂ¸é ¾Æ¾Ö SQL injection°ø°ÝÀÌ ºÒ°¡´ÉÇϰԵdz׿ä?
±×·¯¸é ´Ù¸¥ °ø°Ý±â¹ýÀ¸·Î ÇØÅ·À» ½ÃµµÇؾßÇϴ°ǰ¡¿ä?
2013/07/04  
rubiya ³× ´Ù¸¥ ¹æ¹ýÀ» ã¾Æº¸½Ã´Â°Ô ÁÁ¾Æº¸À̳׿䤻 2013/07/05  
134   ¾ÆÀÌÇÇ ¿ìȸ Á¢¼Ó Áú¹®ÀÔ´Ï´Ù[1]     crankdat
02/08 4138
133   passward cracking Áú¹®ÀÖ½À´Ï´Ù[2]     °æ³²123
01/27 3367
132   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4290
131   ¸ÅÁ÷ÄõÅÍ ¿ìȸ ¹æ¹ý¿¡ ´ëÇØ Áú¹®µå¸³´Ï´Ù.[1]     tpdbs953
10/17 4850
130   À¥ÇØÅ· ¹× ¹æ¾î °øºÎ ¾î¶²°Å ºÎÅÍ ÇÏ¿©¾ß Çϳª¿ä?[1]     jobs7
10/17 3748
129   ÇØÄ¿ °í¼öºÐµé ¼³¸íÁ» ºÎŹµå¸³´Ï´Ù.¤Ð¤Ð wpe-pro ÅäÅ©¿Â[2]     tjrqo12
10/13 7844
128   vbscript·Î Ŭ¶óÀ̾ðÆ® ½Å·ÚÇÒ ¼ö ÀÖ´Â »çÀÌÆ® µî·Ï ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù     lekel09
10/10 4734
127   À¥ ÇØÅ·¿¡ °ü½ÉÀÖÀ¸½ÅºÐ...[2]     hyunmin8
10/02 4114
126   file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.[5]     hyunmin8
09/25 4173
125   sql injection Áú¹®ÀÖ½À´Ï´Ù ¿ìȸ°ü·Ã[1]     Qwed_na
09/04 3453
124   À¥ ÇØÅ· ȨÆäÀÌÁö[3]     xkdlrjxkdltm
08/28 3772
123   Odysseus ¶ó´Â ÇÁ·Î±×·¥¿¡ ´ëÇØ ¿©ÂÞ¾î º¾´Ï´Ù.     ygh159
08/18 3601
122   ftz level5 --> level6¿¡¼­¿ä[1]     31337ÇØÄ¿½º
08/10 3257
121   ÀÌ·±°Íµµ À¥ÇØÅ·Àΰ¡¿ä?[3]     aa136677
08/05 3813
120   ¾È³çÇϼ¼¿ä À̹ø¿¡ ¾Èµå·ÎÀ̵å sql¼­¹ö¸¦ ±¸ÃàÇÏ°Ô µÇ¾ú´Âµ¥¿ä..[2]     ±î¹³´Ù¸£³¢
07/18 4326
119   À¥¼­¹ö ÇØÅ·¹× º¸¾È¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[2]     laysiankim
07/15 3259
118   Æķνº ±ò¾Æ¼­ ½ÇÇà½ÃÄ״µ¥ ¿ÖÀÌ·¯ÁÒ?(»çÁøêó)[1]     ygh159
07/13 4284
117     Æķνº     zen0c1de
07/18 3219
  SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.[3]     kmc8724
07/03 4713
115   ¿î¿µÁßÀÎ À¥»çÀÌÆ®ÀÇ DBÁ¤º¸ ÇØÅ·[2]     cameo305
07/01 8720
[1][2][3][4] 5 [6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org