214, 7/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pr0sp3r
   http://koreasecurity.org
   [re] [Web]php¼Ò½º Çؼ®Á¡ ºÎŹµå¸±°Ô¿ä..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=37 [º¹»ç]


<?php
/**
*   ¼öÁ¤ by ¹Ì´Ï¾î½º at 2011-03-15
**/
$msg = ''; //¹®ÀÚ¿­ ÃʱâÈ­
$table = 'member'; // ºñ±³/»ý¼ºÇÒ Å×À̺í¸í
$dbname = 'apm_db_01';
$connect =mysql_connect('localhost','root','1234'); //DB ¿¬°á

if(mysql_select_db($dbname,$connect)) { // ½ÇÆÐ:FALSE, ¼º°ø:TRUE
  $tb_name=mysql_list_tables($dbname);
  $tb_count=mysql_num_rows($tb_name);
  // var_dump($tb_count);exit; // DB¾ÈÀÇ Å×À̺í¼ö ¹Ýȯ //ex:3
  
  //Å×À̺í¼ö ¸¸Å­ µ¹°³µÊ 0,1,2 <- 3º¸´Ù ¾Æ·¡(3¹ø)
  for($a=0; $a<$tb_count; $a++) // if(){}ÀÚü°¡ Çϳª¹®ÀåÀ¸·Î {}»ý·«°¡´É
    // Å×ÀÌºí ¼ö ¸¸Å­ ¹Ýº¹Çϸç Å×À̺í¸íÀÌ memberÀÎÁö È®ÀÎ
    // mysql_tablename($tb_name,0) -> 1¹ø°Å×À̺íÀÇ À̸§À» ¹Ýȯ //ex: test
    // mysql_tablename($tb_name,1) -> 2¹ø°Å×À̺íÀÇ À̸§À» ¹Ýȯ // ex: member
    if(mysql_tablename($tb_name,$a) == $table) { // $a´Â for¹®À¸·Î ÀÎÇÑ Áõ°¡º¯¼ö
      //½ºÆ®¸µÀ» ½Ì±ÛÄõÅÍ·Î °¨½Î´Â°æ¿ì php°¡ ÆĽÌÀ» ÇÏÁö ¾ÊÀ¸¸ç, ´õºíÄõÅÍÀΰæ¿ì ¹®ÀåÀ»ÆĽÌÇÔ
      $msg = "<h3><br><br><br><br><br><center>¢Ã $table Å×À̺íÀº ÀÌ¹Ì Á¸ÀçÇÕ´Ï´Ù. ";
      $msg .= '<br><hr><br><a href=ex9-5.php>ÁÖ¼Ò ÀÔ·Â È­¸é</a>À¸·Î À̵¿Çϼ¼¿ä.</center></h3>';
      break;
    }

}else{ // DBº¯°æ ½ÇÆÐÀΰæ¿ì
  $msg = "<h3><br><br><br><br><br><center>¢Ã $dbname DB·Î º¯°æÇÏÁö ¸øÇß½À´Ï´Ù. ";
  $msg .= '<br><hr><br><a href=ex9-5.php>ÁÖ¼Ò ÀÔ·Â È­¸é</a>À¸·Î À̵¿Çϼ¼¿ä.</center></h3>';
  die($msg); // die()ÇÔ¼ö exit()ÇÔ¼öÀÇ º°ÄªÀ¸·Î ½ÇÇà ÈÄ ¹«Á¶°Ç ÁߴܵÊ.
}

if(!$msg){
        $sql ="create table $table (
        sno int not null,
        name varchar(10),
        addr varchar(80),
        primary key(sno))";

        //½ÇÆÐ:False ¼º°ø:¸®¼Ò½º ¶Ç´Â TRUE ¹Ýȯ
        $result = mysql_query($sql,$connect) or die("$table »ý¼ººÒ°¡");

        if($result) {
          $msg = "<h3><br><center><br><br><br><br>¢Ã $table Å×À̺íÀ» ¼º°øÀûÀ¸·Î ¸¸µé¾ú½À´Ï´Ù.....<br><hr><br>";
          $msg .=  '<a href=11.php.bak.bak>ÁÖ¼Ò ÀÔ·Â È­¸é</a>À¸·Î À̵¿Çϼ¼¿ä.</center></h3>';
          echo $msg; //result°¡ Àִٴ°ÍÀº »ý¼ºÄõ¸®°¡ Á¤»ó½ÇÇàÇÏ¿´À¸¹Ç·Î À§ÀÇ ¼º°ø¸Þ½ÃÁöÃâ·Â
        }
}else // Çѹ®ÀÚ Çؼ®ÀÎ °æ¿ì {} »ý·«°¡´É
  echo $msg; // msg°¡ Àִٴ°ÍÀº memberÅ×À̺íÀÌ ÀÖÀ¸¹Ç·Î Ãâ·ÂÇÔ.

mysql_close($connect); //DB ¿¬°áÇØÁ¦
?>




===============================================================================

>¾È³çÇϼ¼¿ä..
>php¼Ò½º°¡ ÀÌÇØ°¡ À߾ȵǼ­ Çؼ®Á¡ ºÎŹµå¸®°Ú½À´Ï´Ù.
><?php
>$connect =mysql_connect('localhost','root','12345');
>mysql_select_db('apm_db_01',$connect);
>if($result==1)
>{
>        $tb_name=mysql_list_tables("apm_db_01");
>        $tb_count=mysql_num_rows($tb_name);
>        for($a=0; $a<$tb_count; $a++)
>                if(mysql_tablename($tb_name,$a) == "member") {
>                $flag="ok";
>                break;
>        }
>}
>if($flag !="ok"){
>        $sql ="create table member(
>        sno int not null,
>        name varchar(10),
>        addr varchar(80),
>        primary key(sno))";
>        $result = mysql_query($sql,$connect)
>                or die("<h3><br><br><br><br><br><center>
>        ¢Ã member Å×À̺íÀº ÀÌ¹Ì Á¸ÀçÇÕ´Ï´Ù. <br><hr><br>
>        <a href=ex9-5.php>ÁÖ¼Ò ÀÔ·Â È­¸é</a>À¸·Î À̵¿Çϼ¼¿ä.<center></h3>");
>}
>echo "<h3><br><center><br><br><br><br>¢Ã member Å×À̺íÀ» ¼º°øÀûÀ¸·Î ¸¸µé¾ú½À´Ï´Ù.....<br><hr><br>";
>echo "<a href=11.php.bak.bak>ÁÖ¼Ò ÀÔ·Â È­¸é</a>À¸·Î À̵¿Çϼ¼¿ä.</center></h3>";
>mysql_close($connect);
>?>
>
>for¹®À̶û ifÀÖ´ÂÂÊÀÌ »ì¦ ÀÌÇØ°¡¾È°¡³×¿ä ƯÈ÷ if(mysql_tablename($tb_name,$a) == "member") {
>À̺κпä..
>ºÎŹµå¸®°Ú½À´Ï´Ù.
===============================================================================

  Hit : 4125     Date : 2011/03/15 04:38



    
BkeMan °¨»çÇÕ´Ï´ç~ ¤¾ 2011/03/20  
94   À¥ÇØÅ·ÂÊÀ¸·Î ³ª°¡·Á´Â °íµùÀ©...[1]     lys105
01/28 3217
93   À¥ÇØÅ· ´É·ÂÀÌ µÇ½Ã´ÂºÐ¸¸ º¸¼¼¿ä~     mabini01
09/20 3645
92   ½ÎÀÌ¿ùµå ºñ¹ø¿ä[1]     madhetter
05/15 4224
91   °ú¿¬ ´ëÇü °Ë»ö»çÀÌÆ® ¹ö±×... ¾ÆÁ÷ °¡´ÉÇÒ±î¿ä...?[2]     magpass
10/08 3285
90   teleport pro Áú¹®ÀÔ´Ï´Ù.[1]     mookung
09/19 7098
89   Å©·¡Å· ÇØÁֽǺР±¸ÇØ¿ä (ºÒ¹ýx) »ç·Êµå¸³´Ï´Ù.     mss0812
06/22 3227
88   Äû¸®¹®ÀÌ ¹«½¼ ¶æÀΰ¡¿ä???[4]     my01sun
02/26 4092
87   À¥ÇØÅ· °øºÎ¼ø¼­¸¦ ¾Ë·ÁÁÖ¼¼¿ä..[2]     nooooooob
02/28 4727
86   Æķνº ½ÇÇà °ü·Ã Çؼ­ Áú¹®µå¸³´Ï´Ù.     nouna12
08/13 3975
85   À¥°ø°Ý Top3[3]     Pang
02/07 5082
84   ¾È³çÇϼ¼¿ä ! ¿À´Ã°¡ÀÔÇߴµ¥! ¹è¿ö¾ßÇÒ°ÍÁ» °¡¸£ÃÄÁÖ¼¼¿ä![1]     parani03
04/08 3024
83   À¥ ¾ð¾î Áú¹® µå¸³´Ï´Ù.[5]     pk920207
05/31 3131
82   Á¦¸®ÄÚ Æļ­°¡ ¹«¾ùÀΰ¡¿ä?[21]     poer249
10/29 3939
81   ÀÌ °ø°Ý ¹«½¼ °ø°ÝÀÎÁö ¾Æ½Ã´Â ºÐ[1]     power3122
03/26 3369
    [re] [Web]php¼Ò½º Çؼ®Á¡ ºÎŹµå¸±°Ô¿ä..[1]     pr0sp3r
03/15 4124
79   ÀÎÄÚ±×´ÏÅä ctf write up ¾ø³ª¿ä??[1]     qkqhxla
08/30 3648
78   °Ô½Ã¹° ºñ¹Ð¹øÈ£ ¿ìȸ     qkrrmsgP
11/08 4174
77   °Ô½Ã±Û ºñ¹Ð¹øÈ£ Ç®±â.[2]     qudtn84
03/18 8574
76   sql injection Áú¹®ÀÖ½À´Ï´Ù ¿ìȸ°ü·Ã[1]     Qwed_na
09/04 3500
75   sqlmap °ü·Ã¹× µ¥ÀÌÅͺ£À̽º °ü·Ã¿¡ Áú¹®ÇÕ´Ï´Ù[1]     r0ki
10/10 3404
[1][2][3][4][5][6] 7 [8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org