dragonfly9527 2010-03-29 18:04 采纳率: 100%
浏览 45

已经通过SQL注入攻击的登录代码示例,虽然mysql_real_escape_string ...

I use CodeIgniter, and having trouble with hacking. Is it possible to make SQL Injection to the login code below:

    function process_login()
{
    $username = mysql_real_escape_string($this->input->post('username'));    
    $password  = mysql_real_escape_string(MD5($this->input->post('password')));

    //Check user table
    $query = $this->db->getwhere('users', array('username'=>$username, 'password'=>$password));

    if ($query->num_rows() > 0)
    {
        // success login data

Am I using the mysql_real_escape_string wrong, or what?

  • 写回答

8条回答 默认 最新

  • douhe6255 2010-03-29 18:09
    关注

    Have a look at this old SO question.
    I would use:

    $sql = "SELECT * FROM users WHERE username = '?' AND password= '?'";
    $dbResult = $this->db->query($sql, array($this->input->post('username')),array($this->input->post('password')));
    
    评论

报告相同问题?

悬赏问题

  • ¥15 slam rangenet++配置
  • ¥15 对于相关问题的求解与代码
  • ¥15 ubuntu子系统密码忘记
  • ¥15 信号傅里叶变换在matlab上遇到的小问题请求帮助
  • ¥15 保护模式-系统加载-段寄存器
  • ¥15 电脑桌面设定一个区域禁止鼠标操作
  • ¥15 求NPF226060磁芯的详细资料
  • ¥15 使用R语言marginaleffects包进行边际效应图绘制
  • ¥20 usb设备兼容性问题
  • ¥15 错误(10048): “调用exui内部功能”库命令的参数“参数4”不能接受空数据。怎么解决啊