214, 6/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kmc8724
   SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=151 [º¹»ç]


ÇöÀç ½Ç½ÀÁß¿¡ Àִµ¥
replace(º¯¼ö¸í,"'","")

½Ì±Û ÄõÅÍ -> NULL·Î º¯°æÇϴµî
Ư¼ö¹®ÀÚ¸¦ ÀüºÎ NULL·Î º¯°æÇØ ÁÖ¾ú½À´Ï´Ù.

¹°·Ð ÆÄÀÏÀº aspÀ̱¸¿ä.


ÀÌ »óȲÀ» ¿ìȸÇϰųª ¶Õ´Â ¹æ¹ýÀÌ ¹¹°¡ÀÖ½À´Ï±î?
¾Ë·ÁÁÖ¼¼¿ä

  Hit : 4728     Date : 2013/07/03 03:15



    
rubiya ½Ì±ÛÄõÅÍ ÇѱÛÀÚ¸¦ ġȯÇÒ¶§´Â replace¸¦ ¿ìȸÇÒ¼ö´Â ¾øÁö¸¸ ÀԷ¹޴°÷À» ½Ì±ÛÄõÅÍ·Î ¹­Áö ¾Ê¾Ò´Ù¸é °ø¹é¹®ÀÚ(%20)¸¦ »ç¿ëÇؼ­

select * from table where no=1 ¿¡´Ù°¡

select * from table where no=1 union select ...

ÀÌ·±½ÄÀ¸·Î ¿øÇÏ´Â Äõ¸®¸¦ µ¡ºÙÀÏ ¼ö ÀÖ½À´Ï´Ù.

½Ì±ÛÄõÅÍ ÀÚü¸¦ ÇÊÅ͸µÇÒ°æ¿ì¿¡´Â ±× ¿Ü¿¡´Â °ø°ÝÀÌ ºÒ°¡´ÉÇÑ°É·Î ¾Ë°íÀÖ½À´Ï´Ù.
2013/07/04  
kmc8724 rubiya / ·çºñ¾ß´Ô ¸ÕÀú ¼ÒÁßÇÑ ´äº¯ °¨»çµå¸³´Ï´Ù(_ _) °øºÎ°¡ ‰ç½À´Ï´Ù.
* ÀÌ·±°Íµµ replace·Î ¸·Àº»óÅÂ¸é ¾Æ¾Ö SQL injection°ø°ÝÀÌ ºÒ°¡´ÉÇϰԵdz׿ä?
±×·¯¸é ´Ù¸¥ °ø°Ý±â¹ýÀ¸·Î ÇØÅ·À» ½ÃµµÇؾßÇϴ°ǰ¡¿ä?
2013/07/04  
rubiya ³× ´Ù¸¥ ¹æ¹ýÀ» ã¾Æº¸½Ã´Â°Ô ÁÁ¾Æº¸À̳׿䤻 2013/07/05  
114   ¹ÙÀÌ·¯½ºÄÚµå·Î º¸À̴µ¥ ÄÚµåÇؼ® ºÎŹµå¸³´Ï´Ù[2]     koogee99
05/15 3887
113   À¥ÇØÅ·,º¸¾È/ÇØÅ· À» ¹è¿ì·Á¸é...[1]     kn0ck
01/14 4366
  SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.[3]     kmc8724
07/03 4727
111   À¥ÇØÅ·À» °øºÎÇÏ°í ½ÍÀºµ¥¿ä ¹¹ºÎÅÍ °øºÎÇؾߵɱî¿ä??[2]     kkkod1150
01/27 3191
110   À¥ÇØÅ· ÀÔ¹® Ã¥ÃßõÇØÁÖ¼¼¿ä     kjwp1
02/24 2499
109   À¥Å÷º¸´Ù°¡ ½ºÅÿÀ¹öÇ÷οì‰ç´Âµ¥     kimthon
01/19 3607
108   ÇØÅ· Áú¹®ÀÌ¿ä[4]     kimssi1
03/12 3990
107   ÀÎÁõ¾ø´Â °ü¸®ÀÚ ÆäÀÌÁö¿¡ ´ëÇÑ Áú¹®[1]     killkill14
03/28 3454
106   ¹ÙµÏÀÌ ¿Ãºä¾î Á¦ÀÛÀÚ ¸ð½Ê´Ï´Ù     killerkor
05/25 3052
105   Áú¹®µå¸®°Ú½À´Ï´Ù     khl0803
02/07 3654
104   htmlÄڵ带 Çí½º·Î º¯È¯ÇØ ½ÇÇàÇÒ¼ö ÀÖ³ª¿ä?[2]     kangms0801
01/16 4278
103   webhacking.kr °¡ÀÔ¹®Á¦ Áú¹®µå¸³´Ï´Ù[3]     kangms0801
03/29 5458
102   sessionid´Â ¾î¶²Á¾·ùÀÇ ¾ÏÈ£·Î ÀÎÄÚµù µÇ´Â°Ç°¡¿ä?[2]     kangms0801
04/03 4810
101   sql injectionÀä[3]     kangms0801
09/03 3738
100   php¿¡¼­ Á¡(.)[3]     ka0r1
07/11 3697
99   ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ[2]     ka0r1
04/10 4716
98   ·Î±×¾Æ¿ô ±¸Çö[1]     ka0r1
04/10 3625
97   header¿Í body°¡ ±¸ºÐµÇ¾î ÀÖ´Â ÀÌÀ¯?[4]     ka0r1
04/12 4653
96   SQL Injection[5]     ka0r1
04/14 3615
95   MySQL Áú¹®[2]     ka0r1
04/15 3476
[1][2][3][4][5] 6 [7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org