214, 5/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   ddd.JPG (52.2 KB), Download : 4     [¿À¸¥ÂÊ ¹öÆ° ´­·¯ ´Ù¿î ¹Þ±â]
   MySQL Áú¹®

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=145 [º¹»ç]



select * from books where author='Thomas Down' or '1=1'; ÀÌ °ªÀ» ÀÔ·ÂÇϸé
1=1°ªÀÌ ÂüÀÌ¿©¼­ ³í¸®¿¬»êÀÚ¿¡ ÀÇÇØ ÂüÀ» ¸®ÅÏÇϴµ¥...
ÂüÀ» ¸®ÅÏÇϴµ¥ ¿Ö books µ¥ÀÌÅͺ£À̽ºÀÇ ¸ðµç Á¤º¸°¡ ³ª¿À´Â °É±î¿ä?

  Hit : 3508     Date : 2013/04/15 11:27



    
cd80 sql±¸¹®¿¡¼­ where¹®Àº Äõ¸®ÀÇ °á°úÁß where¹®¿¡ ÂüÀ̵Ǵ °á°úµé¸¸ ¸®ÅÏÀÌ µÇ°Ô ÇÕ´Ï´Ù
select * from books ¸¦ ÇϰԵǸé books Å×À̺íÀÇ ¸ðµç µ¥ÀÌÅ͸¦ Ãâ·ÂÇϴµ¥
¿©±â¼­ where author='Thomas Down' À̶ó´Â Á¶°ÇÀ» °É°ÔµÇ¸é
¸ðµç µ¥ÀÌÅÍÁß author ÇʵåÀÇ µ¥ÀÌÅÍ°¡ Thomas DownÀÎ Ä÷³¸¸À» ¹ÝȯÇÕ´Ï´Ù
±Ùµ¥ À̶§ author = 'Thomas Down' or '1=1'; À» ÇϰԵǸé where¹®Àº Ç×»ó ÂüÀÌ µÇ¹Ç·Î
where¹®¿¡ ÀÇÇØ ÇÊÅ͸µ µÇ´Â °á°ú°¡ ¾ø¾îÁö°Ô µË´Ï´Ù
µû¶ó¼­ Å×ÀÌºí³»ÀÇ ¸ðµç µ¥ÀÌÅÍ°¡ ¹ÝȯµÇ´Â°ÍÀÔ´Ï´Ù
2013/04/16  
ka0r1 cd80 // ¿Í... ¿ª½Ã ¤»¤»¤»¤» ¶¯Å¥! 2013/04/16  
134   webhacking.kr 33-4¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     hygasyde
03/26 4490
133   file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.[5]     hyunmin8
09/25 4230
132   À¥ ÇØÅ·¿¡ °ü½ÉÀÖÀ¸½ÅºÐ...[2]     hyunmin8
10/02 4167
131   À¥½© º»ÁúÀûÀ¸·Î ¹æ¾îÇÒ¼ö ÀÖ´Â ¹æ¹ý?[1]     idbali
07/24 3320
130   googlebig.com/hackgame ¿¡¼­ ³ª¿À´Â XSS¹®Á¦ Áú¹®µå¸³´Ï´Ù.[2]     Ilios
11/23 5829
129   ¸ðÀÇÇØÅ· ¿¬½À¿¡ ÇÊ¿äÇÑ °Í.     inwoox
10/11 4101
128   Ä£±¸°¡ Á¦ÄÄ¿¡ ÇØÅ·ÇÁ·Î±×·¥ ±ò¾Æ³ù´Ù°í ¤Ð¤Ð °í¼ö´Ôµé µµ¿ÍÁÖ¼¼¿ä[2]     ipon7878
06/20 4248
127   KISA ÇØÅ·¹æ¾î ÈÆ·ÃÀå WEB ¹®Á¦¿Í °ü·ÃÇؼ­ Áú¹®µå¸³´Ï´Ù.[1]     jhjang1005
07/16 3504
126   ÇØÄ¿µéÀÇÇØÅ·¹æ½Ä[2]     jhm2882
12/17 5627
125   ÀÇ·ÚÀÔ´Ï´Ù[4]     jjogun
01/30 3047
124   À¥ÇØÅ· ¹× ¹æ¾î °øºÎ ¾î¶²°Å ºÎÅÍ ÇÏ¿©¾ß Çϳª¿ä?[1]     jobs7
10/17 3806
123   Áú¹®ÀÔ´Ï´Ù.     jsw2604
12/27 2813
122   ÀÌ °ø°Ý±¸¹®¿¡ ´ëÇÑ ¼³¸í ºÎŹµå¸³´Ï´Ù.[1]     ju3622
05/05 3566
121   ±Ã±ÝÇؼ­ Áú¹®ÇÕ´Ï´Ù~[2]     ju3622
01/09 2707
120   php¿¡¼­ Á¡(.)[3]     ka0r1
07/11 3739
119   ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ[2]     ka0r1
04/10 4758
118   ·Î±×¾Æ¿ô ±¸Çö[1]     ka0r1
04/10 3668
117   header¿Í body°¡ ±¸ºÐµÇ¾î ÀÖ´Â ÀÌÀ¯?[4]     ka0r1
04/12 4697
116   SQL Injection[5]     ka0r1
04/14 3651
  MySQL Áú¹®[2]     ka0r1
04/15 3507
[1][2][3][4] 5 [6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org