The Web server has a vulnerability that can easily be scanned and tried to inject MySQL:
Today try to scan the real discovery site was injected into the test: paste a piece of code:
GET/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat (User_login,0x3a,user_pass), 7,8,9,10,11,12+from+wp_users--http/1.0 "301 184"-"" mozilla/5.0 (Windows NT 6.0) applewebkit/537.36 (khtml, like Gecko) chrome/32.0.1667.0 safari/537.36 "
The database has been violently cracked: then talk to the developer and ask them to adjust the code:
General injection attacks have several key fields:
Hex Select Concat from INFORMATION_SCHEMA union
You can use Cat Access.log | grep Union View
This article is from the "Little Luo" blog, please be sure to keep this source http://xiaoluoge.blog.51cto.com/9141967/1585611
MySQL Injection attack scan memo;