214, 5/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   ddd.JPG (52.2 KB), Download : 4     [¿À¸¥ÂÊ ¹öÆ° ´­·¯ ´Ù¿î ¹Þ±â]
   MySQL Áú¹®

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=145 [º¹»ç]



select * from books where author='Thomas Down' or '1=1'; ÀÌ °ªÀ» ÀÔ·ÂÇϸé
1=1°ªÀÌ ÂüÀÌ¿©¼­ ³í¸®¿¬»êÀÚ¿¡ ÀÇÇØ ÂüÀ» ¸®ÅÏÇϴµ¥...
ÂüÀ» ¸®ÅÏÇϴµ¥ ¿Ö books µ¥ÀÌÅͺ£À̽ºÀÇ ¸ðµç Á¤º¸°¡ ³ª¿À´Â °É±î¿ä?

  Hit : 3509     Date : 2013/04/15 11:27



    
cd80 sql±¸¹®¿¡¼­ where¹®Àº Äõ¸®ÀÇ °á°úÁß where¹®¿¡ ÂüÀ̵Ǵ °á°úµé¸¸ ¸®ÅÏÀÌ µÇ°Ô ÇÕ´Ï´Ù
select * from books ¸¦ ÇϰԵǸé books Å×À̺íÀÇ ¸ðµç µ¥ÀÌÅ͸¦ Ãâ·ÂÇϴµ¥
¿©±â¼­ where author='Thomas Down' À̶ó´Â Á¶°ÇÀ» °É°ÔµÇ¸é
¸ðµç µ¥ÀÌÅÍÁß author ÇʵåÀÇ µ¥ÀÌÅÍ°¡ Thomas DownÀÎ Ä÷³¸¸À» ¹ÝȯÇÕ´Ï´Ù
±Ùµ¥ À̶§ author = 'Thomas Down' or '1=1'; À» ÇϰԵǸé where¹®Àº Ç×»ó ÂüÀÌ µÇ¹Ç·Î
where¹®¿¡ ÀÇÇØ ÇÊÅ͸µ µÇ´Â °á°ú°¡ ¾ø¾îÁö°Ô µË´Ï´Ù
µû¶ó¼­ Å×ÀÌºí³»ÀÇ ¸ðµç µ¥ÀÌÅÍ°¡ ¹ÝȯµÇ´Â°ÍÀÔ´Ï´Ù
2013/04/16  
ka0r1 cd80 // ¿Í... ¿ª½Ã ¤»¤»¤»¤» ¶¯Å¥! 2013/04/16  
  MySQL Áú¹®[2]     ka0r1
04/15 3508
133   sql injection Áú¹®ÀÖ½À´Ï´Ù ¿ìȸ°ü·Ã[1]     Qwed_na
09/04 3509
132   sql injection °ü·ÃÇؼ­ Áú¹®ÀÔ´Ï´Ù.[2]     cdpython
07/28 3511
131   ƯÁ¤ »çÀÌÆ® ¼Ò½ºÄÚµå º¼¼ö ÀÖ´Â ¹æ¹ýÁ»¿©...[1]     ralehgus123
05/06 3513
130   ÆÄÆøÀÇ Â÷´Ü ±âÁØÀº ¹«¾ùÀΰ¡¿ä ?[1]     $Zero
03/11 3515
129   javascript ¹× xss ¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[1]     haxx
10/23 3516
128   ¾È³çÇϼ¼¿ä. ÀÌ °Ô½ÃÆÇ¿¡ ¸ÂÁö ¾Ê´Â Áú¹®°°Áö¸¸ Áú¹®À» Çϳª Çغ¸·Á°í ÇÕ´Ï´Ù..[1]     Áú¹®ÀÚ
06/21 3526
127   À¥ÇØÅ· °øºÎ Áú¹®ÀÌ¿ä~[2]     ansqudfyd
05/02 3534
126   ¾÷·Îµå Ãë¾àÁ¡¿¡¼­[3]     Sk1y
08/16 3554
125   À¥ÇØÅ· ¹¹ºÎÅÍ....[3]     abnavv
11/04 3558
124   ÀÌ °ø°Ý±¸¹®¿¡ ´ëÇÑ ¼³¸í ºÎŹµå¸³´Ï´Ù.[1]     ju3622
05/05 3566
123   ³×À̹ö ¾ÆÀ̵𰡠ÇØÅ·´çÇß½À´Ï´Ù     rdw0921
09/06 3570
122   ÇØÅ·¿¡ ±âÃʸ¦ ´ëÇؼ­ ¾Ë¾Æº¸·Á°íÇϴµ¥[2]     ggab_coke
05/01 3574
121   À¥ÇØÅ·À» ¹è¿ì°í½Í½À´Ï´Ù..[2]     edustars
05/24 3597
120   ¸ðÀÇÇØÅ· °Ô½ÃÆÇ Çϳª ¸¸µé·Á°í Çϴµ¥ µµ¿ÍÁÖ¼¼¿ä.[1]     ygh357
09/22 3601
119   »çÀÌÆ® Á¤Ã¼¸¦ ¾Ë·ÁÁÖ¼¼¿ä °í¼ö´Ôµé!![1]     hoyadrum
07/10 3602
118   »ó´ë¹æÀÇ ¾ÆÀÌÇÇÁÖ¼Ò¸¦ ÀÌ¿ëÇÏ¿©...[1]     xnm798
07/23 3618
117   ¾ÆÆÄÄ¡ php mysql ¿¬µ¿°ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     Ä¿¼¼¾î
10/19 3633
116   ÀÌ°Ô À¥ÇØÅ·°ú °ü·ÃÀִ°ÇÁö ¸ð¸£°ÚÁö¸¸¿ä[2]     dldduzo11
05/31 3640
115   À¥Å÷º¸´Ù°¡ ½ºÅÿÀ¹öÇ÷οì‰ç´Âµ¥     kimthon
01/19 3645
[1][2][3][4] 5 [6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org