×ªÔØ:¹ØÓÚMYSQLÓï¾ä´æÔÚ×¢Èë©¶´µÄд·¨
×ªÔØ:¹ØÓÚMYSQLÓï¾ä´æÔÚ×¢Èë©¶´µÄд·¨
±¾ÎÄ×÷Õߣºangel
ÎÄÕÂÐÔÖÊ£ºÔ´´
·¢²¼ÈÕÆÚ£º2004-09-16
±¾ÎÄÒѾ·¢±íÔÚ¡¶ºÚ¿Í·ÀÏß¡·7Ô¿¯£¬×ªÔØÇë×¢Ã÷¡£ÓÉÓÚдÁ˺ܾã¬Ëæ×ż¼ÊõµÄ½ø²½£¬±¾ÈËÒ²·¢ÏÖ¸ÃÎÄÀïÓв»ÉÙ´íÎóºÍÂÞàµĵط½¡£Çë¸÷λ¸ßÊÖ¿´Á˲»ÒªÐ¦¡£±¾ÎÄдÓÚ¡¶Advanced SQL Injection with MySQL¡·Ö®Ç°Ò»¸öÔ¡£
ÉùÃ÷
¡¡¡¡±¾ÎĽöÓÃÓÚ½ÌѧĿµÄ£¬Èç¹ûÒòΪ±¾ÎÄÔì³ÉµÄ¹¥»÷ºó¹û±¾È˸Ų»¸ºÔ𣬱¾ÎÄËùÓдúÂë¾ùΪ±¾ÈËËùд£¬ËùÓÐÊý¾Ý¾ù¾¹ý²âÊÔ¡£¾ø¶ÔÕæÊµ¡£Èç¹ûÓÐʲôÒÅ©»ò´íÎ󣬻¶ÓÀ´°²È«ÌìʹÂÛ̳£¨http://www.4ngel.net/forums£©ºÍÎÒ½»Á÷¡£
ǰÑÔ
¡¡¡¡2003Ä꿪ʼ£¬Ï²»¶½Å±¾¹¥»÷µÄÈËÔ½À´Ô½¶à£¬¶øÇÒÑо¿ASPÏÂ×¢ÈëµÄÅóÓÑÒ²Öð½¥¶àÁËÆðÀ´£¬ÎÒ¿´¹ý×îÔçµÄ¹ØÓÚSQL×¢ÈëµÄÎÄÕÂÊÇһƪ99Äê¹úÍâµÄ¸ßÊÖдµÄ£¬¶øÏÖÔÚ¹úÍâµÄÒѾ¯»ð´¿ÇàÁË£¬¹úÄڲſªÊ¼×¢ÒâÕâ¸ö¼¼Êõ£¬ÓÉ´Ë¿´À´£¬¹úÄÚµÄÕâ·½ÃæµÄ¼¼ÊõÏà¶ÔÓÚ¹úÍ⻹ÊÇÓÐÒ»¶ÎºÜ´ó²î¾à£¬»°Ëµ»ØÀ´£¬´ó¼Ò¶ÔSQL×¢Èë¹¥»÷Ò²Ï൱ÊìϤÁË£¬¹úÄÚ¸÷´óÕ¾µã¶¼ÓÐЩ¿°³Æ¾µäµÄ×÷Æ·£¬²»¹ý×÷ΪһƪÍêÕûµÄÎÄÕ£¬ÎÒ¾õµÃ»¹ÊÇÓбØÒªÔÙ˵˵Æä¶¨ÒåºÍÔÀí¡£Èç¹ûÄÄλ¸ßÊÖÒѾ´ïµ½Â¯»ð´¿ÇàµÄµØ²½£¬²»·Á¸ø±¾ÎÄÌôµã´Ì¡£È¨µ±Ö¸µãСµÜ¡£
¹ØÓÚphp+MysqlµÄ×¢Èë
¡¡¡¡¹úÄÚÄÜ¿´µ½php+Mysql×¢ÈëµÄÎÄÕ¿ÉÄܱȽÏÉÙ£¬µ«ÊÇÈç¹û¹Ø×¢¸÷ÖÖWEB³ÌÐòµÄ©¶´£¬¾Í¿ÉÒÔ·¢ÏÖ£¬ÆäʵÕâЩ©¶´µÄÎÄÕÂÆäʵ¾ÍÊÇÒ»¸öÀý×Ó¡£²»¹ýÓÉÓÚ¹úÄÚÑо¿PHPµÄÈ˱ÈÑо¿ASPµÄÈËʵÔÚÉÙÌ«¶à£¬ËùÒÔ£¬¿ÉÄÜûÓÐ×¢Ò⣬¿öÇÒPHPµÄ°²È«ÐÔ±ÈASP¸ßºÜ¶à£¬µ¼ÖºܶàÈ˲»Ïë¿çÔ½Õâ¸öÃż÷¡£
¡¡¡¡¾¡¹ÜÈç´Ë£¬ÔÚPHPÕ¾µãÈÕÒæÔö¶àµÄ½ñÌ죬SQL×¢ÈëÈÔÊÇ×îÓÐЧ×îÂé·³µÄÒ»ÖÖ¹¥»÷·½Ê½£¬ÓÐЧÊÇÒòΪÖÁÉÙ70% ÒÔÉϵÄÕ¾µã´æÔÚSQL Injection©¶´£¬°üÀ¨¹úÄڴ󲿷ְ²È«Õ¾µã£¬Âé·³ÊÇÒòΪMYSQL4ÒÔϵİ汾ÊDz»Ö§³Ö×ÓÓï¾äµÄ£¬¶øÇÒµ±php.iniÀïµÄ magic_quotes_gpc ΪOn ʱ¡£Ìá½»µÄ±äÁ¿ÖÐËùÓÐµÄ ' (µ¥ÒýºÅ), " (Ë«ÒýºÅ), \ (·´Ð±Ïß) and ¿Õ×Ö·û»á×Ô¶¯×ªÎªº¬Óз´Ð±ÏßµÄתÒå×Ö·û¡£¸ø×¢Èë´øÀ´²»ÉÙµÄ×è°¡£
¡¡¡¡ÔçÆÚµÄʱºò£¬¸ù¾Ý³ÌÐòµÄ´úÂ룬Ҫ¹¹Ôì³öûÓÐÒýºÅµÄÓï¾äÐγÉÓÐЧµÄ¹¥»÷£¬»¹ÕæµÄÓеãÀ§ÄÑ£¬ºÃÔÚÏÖÔڵļ¼ÊõÒѾ¹¹Ôì³ö²»´øÒýºÅµÄÓï¾äÓ¦ÓÃÔÚijЩ³¡ºÏ¡£Ö»ÒªÓоÑ飬Æäʵ¹¹ÔìÓÐЧµÄÓï¾äÒ»µãÒ²²»ÄÑ£¬ÉõÖÁ³É¹¦ÂÊÒ²ºÜ¸ß£¬µ«¾ßÌåÇé¿ö¾ßÌå·ÖÎö¡£Ê×ÏÈÒª×ß³öÒ»¸öÎóÇø¡£
×¢£ºÔÚûÓоßÌå˵Ã÷µÄÇé¿öÏ£¬ÎÒÃǼÙÉèmagic_quotes_gpc¾ùΪoff¡£
php+Mysql×¢ÈëµÄÎóÇø
¡¡¡¡ºÜ¶àÈËÈÏΪÔÚPHP+MYSQLÏÂ×¢ÈëÒ»¶¨ÒªÓõ½µ¥ÒýºÅ£¬»òÕßÊÇûÓа취ÏñMSSQ
Ïà¹ØÎĵµ£º
ÓеÄÓû§£¬³öÓÚʹÓÃmysqlÊý¾Ý¿â¿ª·¢ÆäËû³ÌÐòµÄÐèÒª£¬¿ÉÄÜÏ£ÍûÐÞ¸ÄMysqlÊý¾Ý¿âµÄrootÓû§ÃÜÂ룬
ÏÖ×öÒÔϼòҪ˵Ã÷¡£
ÓÉÓÚOAʹÓõÄMysqlÊý¾Ý¿â±»É趨ΪֻÄÜ´Ó±¾»ú·ÃÎÊ£¬ËùÒÔÆÕͨÓû§²»½¨ÒéÐÞ¸ÄÊý¾Ý¿âÃÜÂ룬
ÐÞ¸ÄÊý¾Ý¿âÃÜÂë²¢²»ÊÇΪÁ˸ÄÉÆÏµÍ³°²È«ÐÔµÄÄ¿µÄ¡£
windows-¡µ¿ªÊ¼—¡µÔËÐУ¬ÊäÈëcmd½øÈëÃüÁîÐÐģʽ£¬²¢Ê¹Ó ......
1.´´½¨Ò»¸öjava projectÏîÄ¿pooling
2.ΪÏîÄ¿Ìí¼ÓMySQLÁ¬½ÓÇý¶¯
3.ΪÏîÄ¿Ìí¼ÓÒ»¸öÅäÖÃÎļþdbpool.proprerties
Code
driverClassName=com.mysql.jdbc.Driver
username=root
password=
url=jdbc:mysql://localhost:3306/work
poolSize=10
4.·Ö±ð´´½¨Ò»¸öÁ¬½ÓÀàConnectionPool.javaºÍÒ»¸ö²âÊÔÀàConnectionPoo ......
·Ò룺
InnoDB±í»á°üº¬Ò»¸ö¾Û¼¯Ë÷Òý£¨Êý¾Ý±íµÄÎïÀí´æ´¢Ë³ÐòºÍ±íµÄÂß¼´æ´¢Ë³ÐòÒ»Ö£©
Ò»°ãÊǰ´ÕÕÏÂÃæµÄ¹æÔòÀ´É趨¾Û¼¯Ë÷ÒýµÄ£º
1£¬¼ÙÈç±í°üº¬PRIMARY KEY£¬InnoDBʹÓÃËü×÷Ϊ¾Û¼¯Ë÷Òý
2£¬¼ÙÈç±íûÓж¨ÒåPRIMARY KEY£¬InnoDB½«µÚÒ»¸öÖ»°üº¬NOT NULLÊôÐÔÁеÄUNIQUE index×÷ΪÖ÷¼ü²¢ÇÒ½«ËüÉèÖÃΪ¾Û¼¯Ë÷Òý
3£¬Ç°Á½Õß¶¼²»Âú× ......
conn.php
<?php
/*
* Created on 2010-1-6
* Author:CHAUVET
* Function:Á¬½Ó×Ö·û´®
*/
$conn=@mysql_connect("localhost","root","")or die("Á¬½ÓÊý¾Ý¿â³ö´í£¡");
mysql_select_db("newdb",$conn);
mysql_query("set names 'gb2312'");
function ReplaceSom ......