[20170912]sql injection例子.txt
[20170912]sql injection例子.txt
--//來之tom的例子,做一個記錄.也許以後講解需要!!
1.環境:
SCOTT@book> @ &r/ver1
PORT_STRING VERSION BANNER
------------------------------ -------------- --------------------------------------------------------------------------------
x86_64/Linux 2.4.xx 11.2.0.4.0 Oracle Database 11g Enterprise Edition Release 11.2.0.4.0 - 64bit Production
create or replace procedure inj( p_date in date )
as
l_rec all_users%rowtype;
c sys_refcursor;
l_query long;
begin
l_query := '
select *
from all_users
where created = ''' ||p_date ||'''';
dbms_output.put_line( l_query );
open c for l_query;
for i in 1 .. 5
loop
fetch c into l_rec;
exit when c%notfound;
dbms_output.put_line( l_rec.username || '.....' );
end loop;
close c;
end;
/
SCOTT@book> show parameter nls_date_format
NAME TYPE VALUE
---------------- ------- ---------------------
nls_date_format string YYYY-MM-DD HH24:MI:SS
SCOTT@book> exec inj(sysdate)
select *
from all_users
where created = '2017-09-12 08:47:16'
PL/SQL procedure successfully completed.
--//注意sql語句的輸出.
2.修改環境變數定義:
SCOTT@book> alter session set nls_date_format = 'yyyy-mm-dd hh24:mi:ss"'' or ''a'' = ''a"';
Session altered.
SCOTT@book> exec inj(sysdate)
select *
from all_users
where created = '2017-09-12 08:48:10' or 'a' = 'a'
TEST.....
WYL.....
BI.....
PM.....
SH.....
PL/SQL procedure successfully completed.
來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/267265/viewspace-2144828/,如需轉載,請註明出處,否則將追究法律責任。
相關文章
- False SQL Injection and Advanced Blind SQL InjectionFalseSQL
- MongoDB, no SQL injection?MongoDBSQL
- SQL注射/SQL Injection漏洞SQL
- SQL Injection via DNSSQLDNS
- [20160919]sql注入例子.txtSQL
- Hacking Oracle with Sql InjectionOracleSQL
- Drupal - pre Auth SQL Injection VulnerabilitySQL
- Drupal 7.31 SQL Injection ExpSQL
- DVWA-SQL Injection(SQL隱碼攻擊)SQL
- ecshop /flow.php SQL Injection VulPHPSQL
- ecshop /search.php SQL Injection VulPHPSQL
- ecshop /category.php SQL Injection VulGoPHPSQL
- discuz /faq.php SQL Injection VulPHPSQL
- ecshop /goods.php SQL Injection VulGoPHPSQL
- DVWA靶場實戰(七)——SQL InjectionSQL
- Cacti /graphs_new.php SQL Injection VulnerabilityPHPSQL
- dedecms /member/pm.php SQL Injection VulPHPSQL
- dedecms /plus/feedback.php SQL Injection VulPHPSQL
- dedecms /plus/stow.php Twice SQL InjectionPHPSQL
- dedecms /member/myfriend_group.php SQL Injection VulPHPSQL
- dedecms /member/reg_new.php SQL Injection VulPHPSQL
- dedecms /member/edit_baseinfo.php SQL Injection VulPHPSQL
- phpcms /api/phpsso.php SQL Injection VulPHPAPISQL
- DBMS_SQL例子SQL
- 良精南方cms /inc/Check_Sql.asp SQL Injection Based On CookieSQLCookie
- Zabbix SQL Injection/RCE – CVE-2013-5743SQL
- dedecms /member/uploads_edit.php SQL Injection VulPHPSQL
- ecshop /includes/modules/payment/alipay.php SQL Injection VulPHPSQL
- dedecms /include/helpers/archive.helper.php SQL Injection VulHivePHPSQL
- dedecms /member/flink_main.php SQL Injection VulAIPHPSQL
- ECMall /app/buyer_groupbuy.app.php SQL Injection VulAPPPHPSQL
- PL/SQL 索引表例子SQL索引
- sql loader使用例子SQL
- [20170708]tmux script例子.txtUX
- duxcms SQL Injection In /admin/module/loginMod.class.phpUXSQLPHP
- Spark SQL 最簡單例子SparkSQL單例
- SQL Server遊標使用例子SQLServer
- QIBO CMS SQL Injection Via Variable Uninitialization In \member\special.phpSQLPHP