214, 7/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kmc8724
   SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=151 [º¹»ç]


ÇöÀç ½Ç½ÀÁß¿¡ Àִµ¥
replace(º¯¼ö¸í,"'","")

½Ì±Û ÄõÅÍ -> NULL·Î º¯°æÇϴµî
Ư¼ö¹®ÀÚ¸¦ ÀüºÎ NULL·Î º¯°æÇØ ÁÖ¾ú½À´Ï´Ù.

¹°·Ð ÆÄÀÏÀº aspÀ̱¸¿ä.


ÀÌ »óȲÀ» ¿ìȸÇϰųª ¶Õ´Â ¹æ¹ýÀÌ ¹¹°¡ÀÖ½À´Ï±î?
¾Ë·ÁÁÖ¼¼¿ä

  Hit : 4755     Date : 2013/07/03 03:15



    
rubiya ½Ì±ÛÄõÅÍ ÇѱÛÀÚ¸¦ ġȯÇÒ¶§´Â replace¸¦ ¿ìȸÇÒ¼ö´Â ¾øÁö¸¸ ÀԷ¹޴°÷À» ½Ì±ÛÄõÅÍ·Î ¹­Áö ¾Ê¾Ò´Ù¸é °ø¹é¹®ÀÚ(%20)¸¦ »ç¿ëÇؼ­

select * from table where no=1 ¿¡´Ù°¡

select * from table where no=1 union select ...

ÀÌ·±½ÄÀ¸·Î ¿øÇÏ´Â Äõ¸®¸¦ µ¡ºÙÀÏ ¼ö ÀÖ½À´Ï´Ù.

½Ì±ÛÄõÅÍ ÀÚü¸¦ ÇÊÅ͸µÇÒ°æ¿ì¿¡´Â ±× ¿Ü¿¡´Â °ø°ÝÀÌ ºÒ°¡´ÉÇÑ°É·Î ¾Ë°íÀÖ½À´Ï´Ù.
2013/07/04  
kmc8724 rubiya / ·çºñ¾ß´Ô ¸ÕÀú ¼ÒÁßÇÑ ´äº¯ °¨»çµå¸³´Ï´Ù(_ _) °øºÎ°¡ ‰ç½À´Ï´Ù.
* ÀÌ·±°Íµµ replace·Î ¸·Àº»óÅÂ¸é ¾Æ¾Ö SQL injection°ø°ÝÀÌ ºÒ°¡´ÉÇϰԵdz׿ä?
±×·¯¸é ´Ù¸¥ °ø°Ý±â¹ýÀ¸·Î ÇØÅ·À» ½ÃµµÇؾßÇϴ°ǰ¡¿ä?
2013/07/04  
rubiya ³× ´Ù¸¥ ¹æ¹ýÀ» ã¾Æº¸½Ã´Â°Ô ÁÁ¾Æº¸À̳׿䤻 2013/07/05  
94   sql injection °ü·ÃÇؼ­ Áú¹®ÀÔ´Ï´Ù.[2]     cdpython
07/28 3497
93   sql injection °ø°Ý ¿À·ù¹ÝȯÁú¹®ÀÌ¿ä.[4]     yayaja11
03/21 2815
  SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.[3]     kmc8724
07/03 4754
91   SQL injection ±âº»     ewqqw
03/24 3173
90   sql injection ¹æ¾î ÄÚµå[2]     europa8340
10/04 2836
89   sql injection ½Ç½À ÇÏ·Á´Âµ¥¿ä ...¤Ð¤Ð[1]     wjscjfalsWkd1
06/20 4524
88   sql injectionÀä[3]     kangms0801
09/03 3770
87   sqlmap °ü·Ã¹× µ¥ÀÌÅͺ£À̽º °ü·Ã¿¡ Áú¹®ÇÕ´Ï´Ù[1]     r0ki
10/10 3400
86   sslstripÀ¸·Î Æ®À§ÅÍ ½º´ÏÇÎ Çغ»½ÅºÐ ÀÖ³ª¿ä?     Å×Ã÷
02/21 3383
85   teleport pro Áú¹®ÀÔ´Ï´Ù.[1]     mookung
09/19 7090
84   URLÀ» È°¿ëÇÑ Json ÆÄÀÏ APIºÐ¼®     huny606
12/24 2902
83   vbscript·Î Ŭ¶óÀ̾ðÆ® ½Å·ÚÇÒ ¼ö ÀÖ´Â »çÀÌÆ® µî·Ï ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù     lekel09
10/10 4777
82   webhacking.kr[1]     °¡¸é¼ÓÀǹ̼Ò
04/28 4956
81   webhacking.kr 30¹ø µµ¿òÁ» ÁֽǺÐ...[1]     kumi123
07/30 4552
80   webhacking.kr 33-4¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     hygasyde
03/26 4473
79   webhacking.kr °¡ÀÔ¹®Á¦ Áú¹®µå¸³´Ï´Ù[3]     kangms0801
03/29 5488
78   webhacking.kr °¡ÀÔ¹®Á¦ ¹Ù²¸¼­ Àß ¸ð¸£°Ú½À´Ï´Ù[1]     ¤»z¤Ól¤²q¤Çh¤§e¤Ñm
01/18 5856
77   Webhacking.kr ¹®Á¦¸¦ Ç®´Ù°¡..     alstnsms67
08/02 2714
76   WPA2/PSK °ü·Ã Áú¹®ÀÌ ÀÖ½À´Ï´Ù.     roccafort
04/30 2847
75   wpe°°Àº ÇÁ·Î±×·¥ÀÇ ¿ø¸®¸¦ ÀÌÇØÇÏ·Á¸é..[1]     attainer
11/01 4360
[1][2][3][4][5][6] 7 [8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org