The general idea of SQL injection attack
• Find SQL injection location;
• Judge the background database type;
• Determination of xp_cmdshell performance
• Discovery Web Virtual directory
• Upload asp,php,jsp Trojan;
• Get admin privileges;
? Php
PHP Whole station Anti-injection program, need to require_once the document in the public file
Judge the state of MAGIC_QUOTES_GPC
| code is as follows |
copy code |
if (@get_magic _QUOTES_GPC ()) {
$_get = sec ($_get);
$_post = sec ($_post);
$_cookie = sec ($_cookie);
$_files = sec ($_files);
}
$_server = sec ($_server);
Function sec (& $array) {
//If an array, iterate through the array, recursively call the
if (Is_array ($array)) {
foreach ($array as $k => $v) {
$array [$k] = sec ($v);
}
Else if (is_string ($array)) {
///addslashes function to handle
$array = addslashes ($array);
} else if (Is_numeric ($array)) {
$array = intval ($array);
}
Return $array;
} |
1, the judgment of the parameter of the whole type
When the input argument yy is an integral type, the SQL statement typically looks like this in abc.asp:
SELECT * from table name where field =yy, so you can test the existence of SQL injection with the following steps.
①http://xxx.xxx.xxx/abc.asp?p=yy ' (append a single quote), at this time ABC. The SQL statement in ASP becomes a
SELECT * from table name where Field =yy ', abc.asp run exception;
②http://xxx.xxx.xxx/abc.asp?p=yy and 1=1, the abc.asp runs normally, and is the same as the HTTP://xxx.xxx.xxx/abc.asp?p=YY operation result;
③http://xxx.xxx.xxx/abc.asp?p=yy and 1=2, abc.asp run abnormally;
If the above three steps are fully met, there must be a SQL injection vulnerability in abc.asp.
On top of that we write an integer filter function
| The code is as follows |
Copy Code |
|
function Num_check ($id) {
if (! $id) {
Die (' parameter cannot be empty! ' );
}//IS NULL judgment
else if (Inject_check ($id)) {
Die (' illegal parameters ');
}//Injection judgment
else if (! is_numetic ($id)) {
Die (' illegal parameters ');
}
Digital judgment
$id = Intval ($id);
Integral type
return $id;
}
//character filter functions
function Str_check ($str) {
if (Inject_check ($STR)) {
Die (' illegal parameters ');
}
//injection judgment
$str = Htmlspecialchars ($STR);
//Convert HTML
return $str;
}
Function Search_check ($str) {
$str = Str_replace ("_", "_", $str);
//"_" filter out
$str = str_replace ("%", "%", $str);
//"%" filter out
$str = Htmlspecialchars ($STR);
//Convert HTML
return $str;
}
//form filter function
function Post_check ($str, $min, $max) {
if (isset ($min) && strlen ($STR) < $min) {
Die (' least $min bytes ');
} else if (Isset ($max) && strlen ($STR) > $max) {
Die (' Maximum $max bytes ');
}
Return Stripslashes_array ($STR);
}
|
When the input argument yy is a string, the SQL statement typically looks like this in abc.asp:
SELECT * from table name where field = ' YY ', you can use the following procedure to test whether the SQL injection exists.
①http://xxx.xxx.xxx/abc.asp?p=yy ' (append a single quote), at this time ABC. The SQL statement in ASP becomes a
SELECT * from table name where Field =yy ', abc.asp run exception;
②http://xxx.xxx.xxx/abc.asp?p=yy&;nb ... 39;1 ' = ' 1 ', the abc.asp runs normally, and the result is the same as HTTP://xxx.xxx.xxx/abc.asp?p=YY;
③http://xxx.xxx.xxx/abc.asp?p=yy&;nb ... 39;1 ' = ' 2 ', abc.asp run abnormally;
If the above three steps are fully met, there must be a SQL injection vulnerability in abc.asp.
| The code is as follows |
Copy Code |
|
Anti-injection function
function Inject_check ($sql _str) {
Return eregi (' select|inert|update|delete| ' | /*|*|.. /|. /| Union|into|load_file|outfile ', $sql _str);
Www.111cn.net for filtration, anti-injection
}
Function Stripslashes_array (& $array) {
if (Is_array ($array)) {
foreach ($array as $k => $v) {
$array [$k] = Stripslashes_array ($v);
}
else if (is_string ($array)) {
$array = Stripslashes ($array);
}
return $array;
} |
?>
Good article introduced to the prevention of injection is also more comprehensive, we can test or better way.