douzhi2760 2015-01-23 19:42
浏览 45
已采纳

PHP中的这段代码如何容易受到SQL注入攻击?

I know the basics of SQL Injection and how to avoid it. I know my code is vulnerable, but I'm trying to inject SQL and it is not working. This is about knowing HOW it is vulnerable, because in practice, I cannot do it.

This is the code:

   $email = filter_input(INPUT_GET, 'email');

   if ($email != '') { 
       try {
           $stm1 = $db->query("SELECT * from clients WHERE email =  '$email'");
           $result = $stm1->fetchAll();
       } catch (Exception $ex) {
           echo $ex->getMessage();
       }
  }

I'm trying to inject via this input

<input id="textinput" name="email" type="text">

and I'm using codes like:

'; UPDATE clients set status = 0 WHERE client_id = 1

Note that this is a valid SQL Query.

My real questions are:

  1. Is filter_input preventing anything in this case?
  2. Does PDO '$query' function ONLY allow ONE statement?
  3. If this is not vulnerable in this case, are there any other cases where it would be vulnerable?
  • 写回答

1条回答 默认 最新

  • duanhuang3074 2015-01-23 19:52
    关注

    First, $email = filter_input(INPUT_GET, 'email'); does nothing it's the same as $email = filter_input(INPUT_GET, 'email', FILTER_DEFAULT);, and FILTER_DEFAULT is documented as "do nothing".

    Second, PDO's Query function does appear to support multiple statements (albeit in a rather annoying to use manner, and I can't say I've personally played with it). PHP PDO multiple select query consistently dropping last rowset

    Third, even without multiple statement support, $email could be populated with something like nobody@example.com' OR username='admin to return data you didn't plan on returning to the user.

    Fundamentally: stop worrying about whether bad code is exploitable, and start writing good code instead. Start using properly prepared statements and don't worry about injection anymore.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥30 STM32 INMP441无法读取数据
  • ¥100 求汇川机器人IRCB300控制器和示教器同版本升级固件文件升级包
  • ¥15 用visualstudio2022创建vue项目后无法启动
  • ¥15 x趋于0时tanx-sinx极限可以拆开算吗
  • ¥500 把面具戴到人脸上,请大家贡献智慧
  • ¥15 任意一个散点图自己下载其js脚本文件并做成独立的案例页面,不要作在线的,要离线状态。
  • ¥15 各位 帮我看看如何写代码,打出来的图形要和如下图呈现的一样,急
  • ¥30 c#打开word开启修订并实时显示批注
  • ¥15 如何解决ldsc的这条报错/index error
  • ¥15 VS2022+WDK驱动开发环境