sql injection cheat sheet & tutorial_ vulnerabilities & how to prevent sql injection attacks _...

Upload: nyasha-dombas-sadomba

Post on 07-Jan-2016

22 views

Category:

Documents


0 download

DESCRIPTION

sql injection

TRANSCRIPT

  • Q j &:Vb & PvQ j

    BrowseKnowledge Base

    Application

    Security

    Knowledge Base

    Q j?

    (p://f.v.m/q-j--.m)Q j p f bpp (//.v.m/p/m-

    7 b ffppfm fm -M fpp .

    V b

    B

    p

    b ffp

    pp,&

    m

    ppB

    f

    bppVb

    vpm f

    Pv

    ppp

    -

    ENGLISH (US)

  • SoftwareSecurit

    yTesting Tools

    Web Application

    Vulnerabilities

    Application

    Vulnerabilities

    Buffer

    Overflow

    CRLF Injection

    Cross-Site

    Request

    Forgery

    Cross-Site

    Scripting

    Directory

    Traversal

    Insecure

    Cryptographic

    Storage

    Insufficient

    Transport Layer

    Protection

    Failure to

    Restrict URL

    LDAP Injection

    Malicious Code

    SQL Injection

    Secure

    Development

    Lifecycle

    Data Loss

    Prevention

    Application

    Attack Types

    -/b-pp--)vb b bm b Q mm x b b pp, xp b- b. Q j bpp -pp pp v p f mm q. p f pp x mm . Q j , , p, b- b. mmm fm, Q j v v fm mb, mb f. V f f p (//.v.m/-f--v6--bm-0), Qj f m pv p f bpp vb.

    p f Q j

    Q j f vb b Q p p f Q q. pv p f p Q p p x mm. vb b pvp f p Qp m p b b mm p f. p x mm. Q j xp vb b . Bxp Q j f, , , mf v .

    Q j: MPv p f pp Vb m 20 p f bvb b b Q j, m mm fvb. f, v b f

  • m Pfm V pfm p f pp .

    >

    pv Q j b p f mf b vp p. , Q j xp bpp pp v -pp p p p f q mm b- b.F xmp, p fmm f :"p://.mb.m//.p?=m (//.v.m//q-j)". Q j m"m 1=1". f b pp pp v -pp b, p q xp b, "1=1" . b xmp, b mp f -pp bf q mm.

    Q j V f v Q j m p " Qj?" "m f Q j p" " v Q j ."

    Q j xmp xmp b.

    SQL Injection Explained

    Pm pp ppm b p b, mf m .

    V b

    B

  • QQ = m, PFM m= 0=0 P= 0=0;

    p q q. p x mm b p v f m p f.

    f pv 0=0 m p, q b :

    m, b q , q b. , bb v v fm.

    Pv Q j pv Q j f p p v q p f f f, p x b . pm b v pv. , mm f bpp. , m b f pf pp b

  • pp. m fpv Q j mv p . p pm q P p b m, v p. p f fm j. v,b f b jb ( v f x() m p).

    (p://f.v.m/q-j--.m)

    Q j f Q j pv mm f v bQ j. Q j p f Q j, Q j xmp p v Q j .

    Q j (p://f.v.m/q-j--.m)

    " Q j?" j fp f j pvv p, 'v fp " Q j," v v m m b vb j , pv Q j xmp f Q j. f fp, p . mb b M b .

  • Q jfp b

    M Fm V

    - p- q FP jMb

    b: P(p://p..m//0/106911737219126525828/)

  • () ()

    B vpm

    bpp

    mmp

    -Ppp

    p fV

    Mb

    B xv

    Pf

    vp

    p

    Bmpbp

    M

    P

    -BPfm

    ()

    m()

    bppPmM

    Vpp

    Mbpp

    v

    m

    PmMm

    P

    -P

    p

    b

    ffp

    pp,&

    m

    ppB

    b

    V

    p

    &v

    P

  • p

    pfV

    +1-888-937-0329pp+1-877-837-2203 2015 V, v Mp (/-mp)

    (/-) f (/b/f)