The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


N OT E In the example shown, the double hyphen in the attacker’s input is a



Download 5,76 Mb.
Pdf ko'rish
bet432/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   428   429   430   431   432   433   434   435   ...   875
Bog'liq
3794 1008 4334

N OT E

In the example shown, the double hyphen in the attacker’s input is a

meaningful expression in SQL that tells the query interpreter that the remainder

of the line is a comment and should be ignored. This trick is extremely useful in

some SQL injection attacks, because it enables you to ignore the remainder of

the query created by the application developer. In the example, the application

is encapsulating the user-supplied string in single quotation marks. Because

the attacker has terminated the string he controls and injected some additional

SQL, he needs to handle the trailing quotation mark, to avoid a syntax error

occurring as in the O’Reilly example. He achieves this by adding a double

hyphen, causing the remainder of the query to be treated as a comment. In

MySQL, you will need to include a space after the double hyphen, or use a 


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   428   429   430   431   432   433   434   435   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish