214, 5/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   SQL Injection

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=144 [º¹»ç]


SELECT * FROM user_data WHERE last_name = 'Your Name or 1=1'
À§ÀÇ °ªÀ»...

SELECT * FROM user_data WHERE last_name = 'Your Name' or '1=1'
À§ÀÇ °ªÀ¸·Î ¹Ù²Ù´Ï±ñ ·Î±×ÀÎÀÌ µÇ¾ú½À´Ï´Ù.




'Your Name or 1=1'ÀÌ ±× ÀÚü°¡ ÇÑ ºí·°ÀÌ µÈ´Ù? ºÒ¾ÈÁ¤ÇÏ´Ù?
ÀÌ·¸°Ô ¼³¸íÀÌ µÇ¾î ÀÖ´õ¶ó°í¿ä.

±×·¡¼­ Á¦°¡ 'Your Name' or '1=1'·Î ¹Ù²Ù´Ï±ñ µÇ´Âµ¥...

'Your Name or 1=1' <- ÀÏ´ÜÀº ÀÌ°Í ÀÚü°¡ FALSE°ªÀÌ µÇ¾î¼­ ·Î±×ÀÎÀÌ ºÒ°¡´ÉÇÑ °ÍÀÌ°í

'Your Name' or '1=1' <- ÀÌ°ÍÀº FALSE or TRUE°¡ µÇ¾î¼­, ³í¸®¿¬»ê¿¡ ÀÇÇØ TRUE°¡ µÇ¾î¼­
·Î±×ÀÎÀÌ µÇ´Â °Å¶ó°í ¾Ë°í ÀÖ½À´Ï´Ù.

Á¦°¡ ±Ã±ÝÇÑ °Ç 'Your Name or 1=1' <- ÀÌ°Ô ¿Ö FALSE°¡ µÇ´Â °Ç°¡¿ä?

  Hit : 3652     Date : 2013/04/14 02:53



    
rubiya last_name = 'Your Name or 1=1' Äõ¸® ±×´ë·Î last_name ÀÌ ÄÞ¸¶ »çÀÌ¿¡ ÀÖ´Â 'Your Name or 1=1' ÀÎ °ªÀ» ¹ÝȯÇ϶ó´Â ÀǹÌÀÔ´Ï´Ù.

char a = 'Your Name or 1=1'; ÀÌ°Í°ú ºñ½ÁÇÏ´Ù°í º¸½Ã¸é ÁÁÀ» °Í °°½À´Ï´Ù.
2013/04/14  
ka0r1 Á¦°¡ Áú¹®¿¡ ±ÛÀ» ¿Ã¸®¸é¼­ ´äÀ» ½á¹ö·È³×¿ä ¤»¤»¤»¤»
Your Name or 1=1 (FALSE or TRUE) ==> °á±¹¿£ ³í¸®¿¬»êÀÚ¿¡ ÀÇÇØ FALSE°¡ µÈ´Ù.
ÀÌ·¸°Ô ÀÌÇØÇÏ¸é µÇ³ª¿ä? Your Name ÀÚü°¡ FALSEÀΰǰ¡¿ä?
2013/04/14  
rubiya last_name ÀÇ °ªÀÌ Your Name or 1=1 ÀÌ·¸°Ô 16±ÛÀÚÀÎ °ªÀÌ¿ä!

or À̶ó´Â ´Ü¾î°¡ µé¾îÀÖ´Ù°í Çؼ­ last_nameÀÇ ÀÎÀÚ°¡ ³¡³ª´Â°Ô ¾Æ´Ï¿¹¿ä

'°¡ ¿À´Â¼ø°£ÀÌ ÀÎÀÚ°¡ ³¡³ª¿è

±×¸®°í false or true¸é trueÀԴϴ礻¤»¤»
2013/04/14  
asdf3856 ¼º¸íÀ» ¾î·Æ°Ô ÇϽô°Š°°Àºµ¥.,..
°£´ÜÈ÷ ¼³¸íÇص帲.
SELECT * FROM user_data WHERE last_name = 'Your Name or 1=1'
1.¶ó½ºÆ® ³×ÀÓÀ̶ó´Â º¯¼ö°ª¿¡ true¸¦ ³Ö¾î ¿ìȸ ÇÏ´Â°Ô ¸ñÀû.
2. 'yourName or 1=1' ÀÌ·¸°Ô µÈ°ÍÀº Èí»ç .. last_name = 'asdf'¿Í °°½À´Ï´Ù.

Áï,½Ì±Û ÄõÅÍ (')·Î °ªÀ» ¹­¾î ÁÖ¼Å¾ß µÇ¿ä.. 'yourName' '1=1' ÀÌ·¸°Ô ¹­¾î ÁÖ½ÃÁö ¾ÊÀ¸¸é or¹® ÀÚü°¡ Àǹ̰¡ ¾ø¾îÁö´Âµ¥ or´Â ' 1' '2' ºñ±³ÇÒ º¯¼ö µÎ°³¸¦ ¸¸µé¾îÁּžߵ˴ϴÙ...

SELECT * FROM user_data WHERE last_name = 'Your Name' or '1=1'
' ' or 'true' ·Î ¿ìȸ µÇ´Â °ÅÁ®.. ¸»ÀÌ ÀÌ»óÇѵ¥ ³ªµµ.. ¤Ð
2014/10/18  
asdf3856 ' a' or 'b' ÀÌ·¸°Ô ¹­¾î ÁÖ´ÂÀÌÀ¯´Â ºñ±³ÇÒ ´ë»ó ¼³Á¤ÇÏ½Å´Ù°í º¸¸éµÇ¿ä .
'a or b' ÀÌ·¸°Ô µÇÀÖÀ¸¸é ºñ±³ÇÒ ´ë»óÀ» ãÁö ¸øÇÏ°í 'a or b'¸¦ ÇϳªÀÇ stringÀ¸·Î º»´ä´Ï´Ù.

ps:typeÀÌ ½ºÆ®¸µÀΰ¡?..±â¾ïÀÌ °¡¹°
2014/10/18  
134   webhacking.kr 33-4¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     hygasyde
03/26 4491
133   file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.[5]     hyunmin8
09/25 4233
132   À¥ ÇØÅ·¿¡ °ü½ÉÀÖÀ¸½ÅºÐ...[2]     hyunmin8
10/02 4169
131   À¥½© º»ÁúÀûÀ¸·Î ¹æ¾îÇÒ¼ö ÀÖ´Â ¹æ¹ý?[1]     idbali
07/24 3320
130   googlebig.com/hackgame ¿¡¼­ ³ª¿À´Â XSS¹®Á¦ Áú¹®µå¸³´Ï´Ù.[2]     Ilios
11/23 5831
129   ¸ðÀÇÇØÅ· ¿¬½À¿¡ ÇÊ¿äÇÑ °Í.     inwoox
10/11 4103
128   Ä£±¸°¡ Á¦ÄÄ¿¡ ÇØÅ·ÇÁ·Î±×·¥ ±ò¾Æ³ù´Ù°í ¤Ð¤Ð °í¼ö´Ôµé µµ¿ÍÁÖ¼¼¿ä[2]     ipon7878
06/20 4250
127   KISA ÇØÅ·¹æ¾î ÈÆ·ÃÀå WEB ¹®Á¦¿Í °ü·ÃÇؼ­ Áú¹®µå¸³´Ï´Ù.[1]     jhjang1005
07/16 3508
126   ÇØÄ¿µéÀÇÇØÅ·¹æ½Ä[2]     jhm2882
12/17 5627
125   ÀÇ·ÚÀÔ´Ï´Ù[4]     jjogun
01/30 3050
124   À¥ÇØÅ· ¹× ¹æ¾î °øºÎ ¾î¶²°Å ºÎÅÍ ÇÏ¿©¾ß Çϳª¿ä?[1]     jobs7
10/17 3807
123   Áú¹®ÀÔ´Ï´Ù.     jsw2604
12/27 2814
122   ÀÌ °ø°Ý±¸¹®¿¡ ´ëÇÑ ¼³¸í ºÎŹµå¸³´Ï´Ù.[1]     ju3622
05/05 3567
121   ±Ã±ÝÇؼ­ Áú¹®ÇÕ´Ï´Ù~[2]     ju3622
01/09 2708
120   php¿¡¼­ Á¡(.)[3]     ka0r1
07/11 3741
119   ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ[2]     ka0r1
04/10 4760
118   ·Î±×¾Æ¿ô ±¸Çö[1]     ka0r1
04/10 3669
117   header¿Í body°¡ ±¸ºÐµÇ¾î ÀÖ´Â ÀÌÀ¯?[4]     ka0r1
04/12 4698
  SQL Injection[5]     ka0r1
04/14 3651
115   MySQL Áú¹®[2]     ka0r1
04/15 3510
[1][2][3][4] 5 [6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org