doujiunai2169 2017-11-04 00:02
浏览 22
已采纳

绕过登录代码php [复制]

This question already has an answer here:

i have a problem with mycode '=''or'

$connect= mysqli_connect($host, $user, $password, $database);

if (isset($_POST["sub"])){
    $userr =$_POST["username"];
    $passs =$_POST["password"];
    $password = hash('sha256', $passs);
    $query="select * from user WHERE username='$userr'AND password='$password'";    

    $run=mysqli_query($connect,$query);

                        if(mysqli_num_rows($run))
    {
         header("Location: index.php"); 
        $_SESSION['username']=$userr;
        exit;
    }
    else {
        $pri ='<center><br/> error </center>';
    }
}
mysqli_close($connect);

so when anyone doing bypass using '=''or' it will go to index.php

I don't know really how to fix it ..

</div>
  • 写回答

1条回答 默认 最新

  • dongre6404 2017-11-04 00:09
    关注

    Just properly escape the $userr and $password variables for using in sql statement like this:

     $query="select * from user WHERE username='".mysqli_real_escape_string($connect, $userr)."' AND password='". mysqli_real_escape_string($connect, $password)."'";
    

    You can lookup php mysqli sql injection for more information.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 基于卷积神经网络的声纹识别
  • ¥15 Python中的request,如何使用ssr节点,通过代理requests网页。本人在泰国,需要用大陆ip才能玩网页游戏,合法合规。
  • ¥100 为什么这个恒流源电路不能恒流?
  • ¥15 有偿求跨组件数据流路径图
  • ¥15 写一个方法checkPerson,入参实体类Person,出参布尔值
  • ¥15 我想咨询一下路面纹理三维点云数据处理的一些问题,上传的坐标文件里是怎么对无序点进行编号的,以及xy坐标在处理的时候是进行整体模型分片处理的吗
  • ¥15 CSAPPattacklab
  • ¥15 一直显示正在等待HID—ISP
  • ¥15 Python turtle 画图
  • ¥15 stm32开发clion时遇到的编译问题