English 中文(简体)
绝食:I Can t 绕过过滤器(stripslashes & mysql_real_einski_string)
原标题:SQL injection: I Can t bypass a filter (stripslashes & mysql_real_escape_string)

I m有问题绕过过滤器。

function filter($input) {
    if(get_magic_quotes_gpc())
        $input= stripslashes($input);
    $input = mysql_real_escape_string($input);
    return $input;
}

so the filter uses stripslashes & mysql_real_escape_string which makes it hard to inject

$id = $_GET[ id ];
$id = filter($id);
$query = "select * from users where `id` =  $id  and 1=0 ;"; // for example
$result = mysql_query($query , $connection);

是否有办法绕过它。 事先感谢?

绕过PHP功能过滤器的一种解决办法是脱水灯和喷洒;我sql_real_einski_string。

问题回答

我在谈论这一问题的网络上走了许多文章/职位。

就你的情况而言,不可能根据你提供的确切代码,尝试进行“静脉注射”(我同意“@yourcommonsense”的评论)。

然而,许多专家指出,使用脱硫和我sql_real_爱戴面纱,以防攻击,是危险的,因为在增加新的法典/修正现有法典时,使用这种过滤器的“明显”忘记是非常容易的。 采用参数编制报表

顺便提一下,它们不使用我的sql_* 功能,即过时





相关问题
SQL SubQuery getting particular column

I noticed that there were some threads with similar questions, and I did look through them but did not really get a convincing answer. Here s my question: The subquery below returns a Table with 3 ...

please can anyone check this while loop and if condition

<?php $con=mysql_connect("localhost","mts","mts"); if(!con) { die( unable to connect . mysql_error()); } mysql_select_db("mts",$con); /* date_default_timezone_set ("Asia/Calcutta"); $date = ...

php return a specific row from query

Is it possible in php to return a specific row of data from a mysql query? None of the fetch statements that I ve found return a 2 dimensional array to access specific rows. I want to be able to ...

Character Encodings in PHP and MySQL

Our website was developed with a meta tag set to... <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> This works fine for M-dashes and special quotes, etc. However, I ...

Pagination Strategies for Complex (slow) Datasets

What are some of the strategies being used for pagination of data sets that involve complex queries? count(*) takes ~1.5 sec so we don t want to hit the DB for every page view. Currently there are ~...

Averaging a total in mySQL

My table looks like person_id | car_id | miles ------------------------------ 1 | 1 | 100 1 | 2 | 200 2 | 3 | 1000 2 | 4 | 500 I need to ...

热门标签