SQL×¢Èë¼òµ¥ÔÀí·ÖÎö
SQL×¢Èë¼òµ¥·ÖÎö
ʾÀýÓï¾ä£º
select * from admintable where adminName like '%a%'
ÔÚ²éѯÖÐÎÒÃÇÒ»°ãÔÚaÕâ¸öµØ·½ÓɽçÃæ´«È벻ͬµÄÖµ£¬µ±ÎÒÃÇÔÚaÕâÀï´«ÈëµÄֵΪ“'”µ¥ÒýºÅʱ£¬Æ´´Õ³ÉµÄSQLÓï¾ä¾ÍÈçÏ£º
select * from admintable where adminName like '%'%'
Ö´ÐÐÕâ¾äÓï¾äÎÒÃǻᷢÏÖ³öÏÖÒÔÏÂÒì³££º
ÏûÏ¢ 105£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
×Ö·û´® '
' ºóµÄÒýºÅ²»ÍêÕû¡£
ÏûÏ¢ 102£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
'
' ¸½½üÓÐÓï·¨´íÎó¡£
ÒòΪµ¥ÒýºÅµÄ¼ÓÈëÊÇÔ±¾ÍêÕûµÄSQLÓï¾äÆ´´Õ²»ÔÙÍêÕû£¬Òò´Ëµ¼ÖÂÒÔÉÏÒì³£¡£
¶øÒ»°ãºÚ¿ÍÔÚ¼òµ¥µÄ³¢ÊÔ×¢Èëʱ£¬ÔÚ½çÃæµÄÊäÈë´¦£¨ÈçURLµÄ²ÎÊý£¬Îı¾¿òµÄÊäÈëµÈ£©Ö±½ÓÊäÈëµ¥ÒýºÅÀ´²âÊÔÊÇ·ñ»áÒý·¢SQLÒì³££¬¸ù¾ÝÒ³ÃæµÄ´íÎó´úÂëÕ¹ÏÖÀ´ÅжÏÊÇ·ñ´æÔÚSQL×¢Èë©¶´£¬ÀýÈç»áÖ±½ÓÔÚÒ³ÃæÖгöÏÖSQLµÄÒì³£´úÂë»òÖ±½ÓÌø×ªµ½´íÎóÒ³Ãæ¡£µ±±»ÈÏΪ´æÔÚSQL×¢Èë©¶´Ê±£¬ÄÇô½«²»ÔÙÊÇÊäÈëµ¥ÒýºÅÁË£¬¶øÊÇÊäÈëÏà¹ØµÄSQLÖ´ÐÐÓï¾ä¡£
ÓÚÊǵ±ÎÒÃÇ´«È벻ͬµÄÖµÀýÈç
' or 1=1 ;delete admintable where 1=1 or ''='
µÃµ½µÄSQLÓï¾ä¾ÍÈçÏ£º
select * from admintable where adminName like '%' or 1=1 ;delete admintable where 1=1 or ''='%'
¶øÕâ¾äSQLµÄÖ´ÐÐЧ¹û¾ÍÓÐÁ½¸ö£º
1¡¢select * from admintable where adminName like '%' or 1=1 ;
--²éѯadmintable
2¡¢delete admintable where 1=1 or ''='%'
--½«admintableÇå¿Õ
Ò²¾ÍÊÇ˵Èç¹û°Ñdelete admintable where 1=1 Õâ¾äSQLÀ©Õ¹Ð޸ĵϰ£¬¿ÉÒÔÖ´ÐÐÔöɾ¸ÄµÈ²Ù×÷ÁË£¬ÀýÈçSQL2000ÖеÄXP_CMDShellÃüÁÄÜÖ±½ÓÖ´ÐÐCMDÃüÁį̂µÄCMDÃüÁÀ´ÊµÏÖÖ±½Ó¶Ô·þÎñÆ÷µÄ¿ØÖƵȡ£
ÖÁÓÚÈçºÎ±©Â¶³öÊý¾Ý¿âµÄ¸÷¸ö±íµÄÃû×ֵȣ¬¿ÉÒÔͨ¹ýö¾Ù²Â²âµÈ·½Ê½ÊµÏÖ£¬ÍøÂçÉÏÒѾÓÐÏà¹ØµÄSQL×¢È빤¾ß¿É¹©Ö±½ÓʹÓá£
µ±ÎÒÃǵÄÍøÕ¾´æÔÚSQL×¢Èë©¶´Ê±£¬×îºÃÐÞ¸ÄÏà¹ØµÄµ×²ã´úÂë»òÕßʹÓÃÏà¹ØµÄ¼à¿Ø¹¤¾ßÀ´ÐÞ¸´¡£Ò»¸öÍøÕ¾±»ÈëÇÖ²¢²»ÊÇºÚ¿ÍµÄ´í£¬¶øÊÇ·þÎñÆ÷¹ÜÀíÔ±ºÍÍøÕ¾¿ª·¢ÈËÔ±ÈÇϵĻö¡£
ÈçÓдíÎ󣬾´ÇëÖ¸Õý¡£
Ïà¹ØÎĵµ£º
Ò» sqlÓï¾äµÄÖ´Ðв½Öè
1£©Óï·¨·ÖÎö£¬·ÖÎöÓï¾äµÄÓï·¨ÊÇ·ñ·ûºÏ¹æ·¶£¬ºâÁ¿Óï¾äÖи÷±í´ïʽµÄÒâÒå¡£
2£© ÓïÒå·ÖÎö£¬¼ì²éÓï¾äÖÐÉæ¼°µÄËùÓÐÊý¾Ý¿â¶ÔÏóÊÇ·ñ´æÔÚ£¬ÇÒÓû§ÓÐÏàÓ¦µÄȨÏÞ¡£
3£©ÊÓͼת»»£¬½«Éæ¼°ÊÓͼµÄ²éѯÓï¾äת»»ÎªÏàÓ¦µÄ¶Ô»ù±í²éѯÓï¾ä¡£
4£©±í´ïʽת»»£¬ ½«¸´Ô SQL ±í´ïʽת»»Îª½Ï¼òµ¥µÄµÈЧÁ¬½Ó±í´ïʽ¡ ......
1.µ½http://www.oracle.com/technology/global/cn/software/tech/oci/instantclient/htdocs/winsoft.htmlÏÂÔØ
11.1.0.7.0 °æµÄ¼´Ê±¿Í»§¶Ë³ÌÐò°ü — Basic£¨²»ÊÇBasic Lite£©
2.½«ÏÂÔØµ½µÄÎļþ½âѹ£¬½âѹºóÎÒ½«Ä¿Â¼instantclient_11_1ÀïµÄÈ«²¿Îļþ¿½±´µ½ÁËÒ»¸öеÄĿ¼£ºE:\programs\OracleClient¡£ÄãÒ²¿ÉÒÔ²»¿½±´£¬Ö ......
ÔÚ²éѯ·ÖÎöÆ÷ÖÐÊäÈëÒÔÏÂÄÚÈÝ£º
set statistics profile on
set statistics io on
set statistics time on
go
go
set statistics profile off
set statistics io off
set statistics time off ......
д³ÌÐòµÄÈË£¬ÍùÍùÐèÒª·ÖÎöËùдµÄSQLÓï¾äÊÇ·ñÒѾÓÅ»¯¹ýÁË£¬·þÎñÆ÷µÄÏìӦʱ¼äÓжà¿ì£¬Õâ¸öʱºò¾ÍÐèÒªÓõ½SQLµÄSTATISTICS״ֵ̬À´²é¿´ÁË¡£
ͨ¹ýÉèÖÃSTATISTICSÎÒÃÇ¿ÉÒԲ鿴ִÐÐSQLʱµÄϵͳÇé¿ö¡£Ñ¡ÏîÓÐPROFILE£¬IO £¬TIME¡£½éÉÜÈçÏ£º
SET STATISTICS PROFILE ON£ºÏÔʾ·ÖÎö ......
ÔÚDELPHIÖг£³£ÒªÓõ½ADOQUERYÖеÄSQLÓï¾äÔö¼ÓÐÅÏ¢ºóÖ´ÐУ¬µ±ÒªÇóÔö¼ÓÌõ¼þ£¨Èç²ÎÊýʱ£©ÖмäµÄ¼ä¸ôºÜÖØÒª£¬¸ã²»ºÃ¾ÍÒª³ö´í£ºÏ¾ÙÀý˵Ã÷ÎÒÒª±í´ïµÄÒâ˼£º
È磺һ¸ö±í:student ÓÐ ksh,xm,xb,lqzy,lqcc¼¸¸ö×ֶΣ¬¶¼Îª×Ö·ûÐÍ¡£ÏÖÒªÇó°´xb·Ö×éͳ¼ÆÈËÊý£¬Í¬Ê±lqccÒªÇóÏÞ¶¨Ìõ¼þ¡£
Ò»°ãÇé¿öϵÄSQLÓï¾äÓ¦¸ÃΪ£º select xb,count(*) ......