Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

Ó¦ÓÃIDS·ÀÖ¹SQL×¢Èë¹¥»÷

Ó¦ÓÃIDS·ÀÖ¹SQL×¢Èë¹¥»÷
http://www.cnhacker.com/Hacker/Skills/200807/t20080731_6187.html
Ä¿Ç°£¬Õë¶ÔÓ¦Óü°Æäºǫ́Êý¾Ý¿âµÄÓ¦Óü¶ÈëÇÖÒѾ­±äµÃÔ½À´Ô½²þâ±£¬ÈçSQL×¢Èë¡¢¿çÕ¾µã½Å±¾¹¥»÷ºÍδ¾­ÊÚȨµÄÓû§·ÃÎʵȡ£ËùÓÐÕâЩÈëÇÖ¶¼ÓпÉÄÜÈƹýǰ̨°²È«ÏµÍ³²¢¶ÔÊý¾ÝÀ´Ô´·¢Æð¹¥»÷¡£
ΪÁ˶Ը¶ÕâÀàÍþв£¬ÐÂÒ»¼¶±ðµÄ°²È«ÍÑÓ±¶ø³ö£¬Õâ¾ÍÊÇÓ¦Óð²È«¡£ÕâÖÖ°²È«¼¼Êõ½«´«Í³µÄÍøÂçºÍ²Ù×÷ϵͳ¼¶ÈëÇÖ̽²âϵͳ(IDS)¸ÅÄîÓ¦ÓÃÓÚÊý¾Ý¿â(¼´Ó¦ÓÃ)¡£Óëͨ³£µÄÍøÂç»ò²Ù×÷ϵͳ½â¾ö·½°¸²»Í¬µÄÊÇ£¬Ó¦ÓÃIDSÌṩÖ÷¶¯µÄ¡¢Õë¶ÔSQLµÄ±£»¤ºÍ¼àÊÓ£¬¿ÉÒÔ±£»¤ÊýÒÔǧ¼ÆµÄÔ¤ÏÈ°ü×°»ò×ÔÐпª·¢µÄWebÓ¦Óá£ÀýÈ磬ӦÓÃIDS¿ÉÒÔ¼àÊӺͷÀ»¤¹Ø¼üµÄÊý¾Ý£¬Ê¹ÄÇЩÕë¶ÔÊý¾Ý¿âµÄ¹¥»÷£¬È绺³åÇøÒç³öºÍWebÓ¦Óù¥»÷µÈÎÞ·¨¶ÔÊý¾Ý¿âÔì³ÉÕæÕýµÄË𺦣¬¶øÇÒÓ¦ÓÃIDS»¹¿ÉÒÔ¶ÔÕâЩʼþ½øÐÐÉó²é¡£
Ó¦Óð²È«ÓëÍøÂçºÍÖ÷»ú°²È«Ö®¼ä´æÔںܴóµÄÇø±ð¡£Ó¦ÓÃÊÇǧ²îÍò±ðµÄ£¬µ«¹¥»÷µÄÄ¿±ê×ÜÊÇÏàͬµÄ£¬Ò²¾ÍÊÇÈëÇÖÊý¾Ý¿â¡£ÓÉÓÚÓ¦ÓÃʹÓÃSQLÓëÊý¾Ý¿â½øÐÐͨÐÅ£¬Òò´ËºÃµÄÓ¦ÓÃIDSÓ¦µ±Äܹ»½âÎöSQL£¬²¢ÇÒÌṩһÖÖÄܹ»Àí½âÁ÷Á¿µÄÄÚÈÝ£¬ÇÒÓÖÄÜÓëÓ¦Óû®Çå½çÏߵĿ͹۱£»¤²ã¡£
¶àÊýÓ¦ÓÃIDS¶¼ÓÐÈý¸ö×é¼þ¡£µÚÒ»¸öÊÇ»ùÓÚÍøÂç»òÖ÷»úµÄ´«¸ÐÆ÷¡£ÍøÂç´«¸ÐÆ÷Á¬½Óµ½½»»»»úÉϵÄÒ»¸ö¶Ë¿ÚÉÏ£¬¸Ã¶Ë¿ÚµÄÅäÖþö¶¨Ëü¿ÉÒԲ鿴µ½Êý¾Ý¿âÄÚµÄËùÓÐÁ÷Á¿¡£Ïà±È֮ϣ¬Ö÷»ú´«¸ÐÆ÷Ö±½ÓפÁôÔÚÓ¦ÓÃÉÏ¡£´«¸ÐÆ÷¿ÉÒÔÊÕ¼¯SQL½»Òײ¢¶ÔÆä½øÐнâÎö£¬È»ºó¾ö¶¨ÊÇ·ñÓ¦µ±Õë¶Ô¸ÃÁ÷Á¿·¢³ö¾¯±¨¡£Èç¹ûÓбØÒª·¢³ö¾¯¸æ£¬¾¯¸æ»á±»´«µÝ¸øÏÂÒ»¸ö×é¼þ£¬¼´¿ØÖÆ̨·þÎñÆ÷¡£Õą̂·þÎñÆ÷´æ´¢Ê¼þÐÅÏ¢£¬²¢ÇÒÊDzßÂÔÅäÖúÍÉý¼¶µÈ´«¸ÐÆ÷ά»¤»î¶¯µÄÖÐÐĵ㡣ӦÓÃIDSÖеĵÚÈý¸ö×é¼þÊÇWebä¯ÀÀÆ÷£¬¹ÜÀíÔ±¿ÉÒÔÀûÓÃËüÀ´ÐÞ¸ÄIDSÉèÖá¢ÊµÊ±¼àÊÓʼþ²¢Éú³É±¨¸æ¡£
ÒÔSQL×¢Èë¹¥»÷ΪÀý£¬¹¥»÷Õß»áÊÔͼÈƹýWeb·þÎñÆ÷¶¨ÒåµÄSQLÓï¾ä£¬Ä¿µÄ¾ÍÊÇҪעÈë×Ô¼ºµÄÓï¾ä¡£¼ÙÉèÒªÊäÈëµÄÓû§ÃûΪBob£¬¿ÚÁîΪHardtoguess¡£
µ±¿´µ½ÕâЩÊäÈëµÄÄÚÈݺó£¬Êý¾Ý¿â¾Í»áÕÒµ½WebUsers ÐÐÖÐÓë֮ƥÅäµÄÄÚÈÝ£¬È»ºó¸ÃÓ¦Óûá¶ÔÓû§½øÐÐÑéÖ¤¡£ÎªÁËÈëÇÖÊý¾Ý¿â£¬SQL×¢Èë¹¥»÷»áÆÛÆ­Ó¦Ó㬲¢Ê¹Ö®ÏàÐÅ×Ô¼ºÒѾ­Ìá½»ÁËÕýÈ·µÄÖ¤Êé¡£ÀýÈ磬¹¥»÷ʹÓõĿÚÁîÊÇ‘blah’»ò‘A’=‘A’£¬Òò´Ë¹¥»÷ʱ´´½¨µÄSQLÓï¾ä¿ÉÄÜ»áÊÇ:SELECT * from WebUsers WHERE Username=‘Bob’ AND Password=‘blah’ OR‘A’=‘A’¡£
´ÓÂß¼­ÉÏÀ´·ÖÎö‘A’=‘A’ÓÀÔ¶¶¼ÊÇTRUE£¬¶øWHERE×Ó¾äÒ²¿


Ïà¹ØÎĵµ£º

¾­µäSQLÓï¾ä´óÈ«

Ò»¡¢»ù´¡
1¡¢ËµÃ÷£º´´½¨Êý¾Ý¿â
CREATE DATABASE database-name
2¡¢ËµÃ÷£ºÉ¾³ýÊý¾Ý¿â
drop database dbname
3¡¢ËµÃ÷£º±¸·Ýsql server
--- ´´½¨ ±¸·ÝÊý¾ÝµÄ device
USE master
EXEC sp_addumpdevice 'disk', 'testBack', 'c:\mssql7backup\MyNwind_1.dat'
--- ¿ªÊ¼ ±¸·Ý
BACKUP DATABASE pubs TO testBack
4¡¢Ëµ ......

sql¾­µäÓï¾ä

SQL·ÖÀࣺ
DDL—Êý¾Ý¶¨ÒåÓïÑÔ(CREATE£¬ALTER£¬DROP£¬DECLARE)
DML—Êý¾Ý²Ù×ÝÓïÑÔ(SELECT£¬DELETE£¬UPDATE£¬INSERT)
DCL—Êý¾Ý¿ØÖÆÓïÑÔ(GRANT£¬REVOKE£¬COMMIT£¬ROLLBACK)
Ê×ÏÈ,¼òÒª½éÉÜ»ù´¡Óï¾ä£º
1¡¢ËµÃ÷£º´´½¨Êý¾Ý¿â
CREATE DATABASE database-name
2¡¢ËµÃ÷£ºÉ¾³ýÊý¾Ý¿â
drop database dbname ......

SQL¾«»ªÊÕ¼¯

order by µÄÊýÖµÐÍÁé»îʹÓÃ
select * from table_a where id=p_id order by decode(º¯Êý,'asc',1,'desc',-1)*jsny;
¿ØÖÆÊÔͼµÄ·ÃÎÊʱ¼ä£º
6.create view ...
as
select ... from where exists(select x from dual where sysdate>=8:00am and sysdate<=5:00pm)
ÃîÓÃdecodeʵÏÖÅÅÐò
select * from tabnam ......

SQLÃæÊÔÌâС½á

 
ÎÒÏëÃæÊÔ¹ýÈí¼þ¿ª·¢µÄÅóÓѶ¼»áÅöµ½sql·½ÃæµÄÃæÊÔÌ⣬Õâ¸ö¿ÉÒÔ˵ÊÇÃæÊԱؿ¼µÄ¡£ÕâÀïÄü¸¸öÀý×Ó¿ªÍØÒ»ÏÂ˼·¡£
1.      
ÓÐÕâÑùÒ»Õűí
½ÌʦºÅ
ÐÇÆÚ
ÊÇ·ñÓпÎ
1
1
ÓÐ
2
3
ÓÐ
1
2
ÓÐ
1
2
ÓÐ
ÒªµÃ³öÕâÑùµÄÊý¾Ý£º
ÐÕÃû
ÐÇÆÚÒ»
ÐÇÆÚ¶þ
ÐÇÆÚÈý
ÐÇÆÚËÄ
ÐÇÆÚÎå
1
1 ......

½²½âSQL ServerÊý¾Ý¿â±»¹ÒÂíµÄ½â¾ö·½°¸

½²½âSQL ServerÊý¾Ý¿â±»¹ÒÂíµÄ½â¾ö·½°¸
http://www.cnhacker.com/Security/Plan/200808/t20080822_6383.html
°¸Àý£ºÒ»¸öÍøÕ¾ÔâÓöÈëÇÖ£¬ÆÆ»µÏ൱ÑÏÖØ£¬SQLÊý¾Ý¿â±»¹ÒÂí£¬ËùÓеıíÀïÃæ´ó²¿·Ö×ֶζ¼±»¶à´ÎÖظ´²åÈë¹ÒÂí´úÂ룬²é¿´ÈÕÖ¾£¬»¹ºÃûÓÐÉæ¼°µ½·þÎñÆ÷µÄ°²È«£¬Ö»ÊÇÊý¾Ý¿âÄÇÀï³öÏÖÁ˺ܶàÒì³£¾¯¸æ¶øÒÑ£¬Íøվȷʵ´æÔÚ©¶´ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ