๊ด€๋ฆฌ ๋ฉ”๋‰ด

๋ชฉ๋กinjection๊ณต๊ฒฉ (1)

<Hello Hosung๐Ÿ˜Ž/>

[CS ์ง€์‹]SQL Injection

SQL Injection ์€ ๋ง ๊ทธ๋Œ€๋กœ SQL ๊ตฌ๋ฌธ์˜ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ๊ณต๊ฒฉํ•˜๋Š” ๋ฐฉ์‹์ž…๋‹ˆ๋‹ค.์˜ˆ๋ฅผ ๋“ค์–ด ๋กœ๊ทธ์ธ์‹œ ํ•ด๋‹น ์œ ์ €์˜ ์•„์ด๋””์™€ ํŒจ์Šค์›Œ๋“œ๊ฐ€ ๋งž๋Š”์ง€ ๊ฒ€์‚ฌํ•˜๊ธฐ ์œ„ํ•ด ์•„๋ž˜์™€ ๊ฐ™์€ ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•  ๊ฒƒ์œผ๋กœ ์ƒ๊ฐ๋ฉ๋‹ˆ๋‹ค.//SELECT * FROM USER WHERER ID='' AND PW =''; ๋งŒ์•ฝ ์•„์ด๋”” ์ž…๋ ฅ์ฐฝ์— TESTID' ๋ฅผ ์ž…๋ ฅํ•˜๊ฒŒ ๋˜๋ฉด '๊ฐ€ ํ•˜๋‚˜ ๋”์ฐํ˜€์„œ ์˜ค๋ฅ˜//SELECT * FROM USER WHERER ID='TESTID'' AND PW ='';๋งŒ์•ฝ ์•„์ด๋”” ์ž…๋ ฅ์ฐฝ์— ' or 1=1# ๋ฅผ ์ž…๋ ฅํ•˜๊ฒŒ ๋˜๋ฉด # ๋’ค๋กœ ์ฃผ์„์ฒ˜๋ฆฌ ๋˜์–ด์„œ ์ „์ฒด ๋ฐ์ดํ„ฐ๊ฐ€ ์ถœ๋ ฅ๋˜์–ด ๋กœ๊ทธ์ธ์ด ๋ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. //SELECT * FROM USER WHERER ID='' or 1=1#' AND PW ='';๊ทธ ์™ธ ์—ฌ๋Ÿฌ๊ฐ€์ง€ sql ..

๐Ÿ“– CS Information 2024. 8. 15. 20:32