Java·ÀÖ¹SQL×¢Èë
SQL×¢ÈëÊÇ×î³£¼ûµÄ¹¥»÷·½Ê½Ö®Ò»,Ëü²»ÊÇÀûÓòÙ×÷ϵͳ»òÆäËüϵͳµÄ©¶´À´ÊµÏÖ¹¥»÷µÄ,¶øÊdzÌÐòÔ±ÒòΪûÓÐ×öºÃÅжÏ,±»²»·¨
Óû§×êÁËSQLµÄ¿Õ×Ó,ÏÂÃæÎÒÃÇÏÈÀ´¿´ÏÂʲôÊÇSQL×¢Èë:
±ÈÈçÔÚÒ»¸öµÇ½½çÃæ,ÒªÇóÓû§ÊäÈëÓû§ÃûºÍÃÜÂë:
Óû§Ãû: ' or 1=1 --
ÃÜ Âë:
µãµÇ½,ÈçÈôûÓÐ×öÌØÊâ´¦Àí,¶øÖ»ÊÇÒ»Ìõ´øÌõ¼þµÄ²éѯÓï¾äÈç:
String sql="select * from users where username='"+userName+"' and password='"+password+"' "
ÄÇôÕâ¸ö·Ç·¨Óû§¾ÍºÜµÃÒâµÄµÇ½½øÈ¥ÁË.(µ±È»ÏÖÔÚµÄÓÐЩÓïÑÔµÄÊý¾Ý¿âAPIÒѾ´¦ÀíÁËÕâЩÎÊÌâ)
ÕâÊÇÎªÊ²Ã´ÄØ?ÎÒÃÇÀ´¿´¿´ÕâÌõÓï¾ä,½«Óû§ÊäÈëµÄÊý¾ÝÌæ»»ºóµÃµ½ÕâÑùÒ»ÌõÓï¾ä:
select * from users where username='' or 1=1 --' and password=''
ΪÁ˸üÃ÷°×Щ£¬¿ÉÒÔ½«Æä¸´ÖƵ½SQL·ÖÎöÆ÷ÖУ¬½«»á·¢ÏÖ£¬ÕâÌõÓï¾ä»á½«Êý¾Ý¿âµÄÊý¾ÝÈ«²¿¶Á³öÀ´£¬ÎªÊ²Ã´ÄØ£¿
ºÜ¼òµ¥,¿´µ½Ìõ¼þºóÃæ username='' or 1=1 Óû§ÃûµÈÓÚ '' »ò 1=1 ÄÇôÕâ¸öÌõ¼þÒ»¶¨»á³É¹¦£¬È»ºóºóÃæ¼ÓÁ½¸ö-£¬ÕâÒâζ×Å
ʲô£¿Ã»´í£¬×¢ÊÍ£¬Ëü½«ºóÃæµÄÓï¾ä×¢ÊÍ£¬ÈÃËûÃDz»Æð×÷Óã¬ÕâÑù¾Í¿ÉÒÔ˳ÀûµÄ°ÑÊý¾Ý¿âÖеÄÊý¾Ý¶ÁÈ¡³öÀ´ÁË¡£
Õ⻹ÊDZȽÏÎÂÈáµÄ£¬Èç¹ûÊÇÖ´ÐÐ
select * from users where username='' ;DROP Database (DB Name) --' and password=''
.......ÆäËûµÄÄú¿ÉÒÔ×Ô¼ºÏëÏ󡣡£¡£
ÄÇôÎÒÃÇÔõôÀ´´¦ÀíÕâÖÖ
Ïà¹ØÎĵµ£º
½ñÌìÎÒÔÚ×ö·É»ú¡£ÎªÊ²Ã´ËµÎÒÔÚ×ö·É»úÄØ£¡ÒòΪÕâÊÇÎÒ½ø´«ÖDz¥¿ÍÒÔÀ´£¬¸öÈ˸оõ·Ç³£ÖØÒªµÄÒ»ÌÿΣ¬µ«ÊÇÎÒ²»ÄÜÒ»ÏÂ×Ó¼ÇסËùËùÓеĶ«Î÷£¬×òÌìÍíÉÏ£¬¿´ÊÓÆµ¿´µ½ÍíÉÏÈýµã£¬½ñÌìÉϿκÜÏ뼯ÖÐ×¢ÒâÁ¦£¬µ«ÊÇ×îÖÕ»¹ÊÇÈ̲»×¡´òÁËî§Ë¯£¬µ«½ñÌìµÄµÄ¿Î¸øÎҵĸоõÊǷdz£¾ßÓÐÁ¬¹áÐÔ£¬Ç°ÃæµÄ¿ÎÈç¹ûÌýµÃ²»ÊǺÜÇ ......
--ÒÔÏÂÎÄÕÂÎª×ªÔØ.
SQL×¢Èë©¶´È«½Ó´¥——ÈëÃÅÆª
ZDNet Èí¼þƵµÀ ¸üÐÂʱ¼ä£º2007-08-20 ×÷ÕߣºCSDN À´Ô´£ºCSDN
±¾ÎĹؼü´Ê£ºÂ©¶´ SQL Server SQL
Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚÕâ¸öÐÐÒµµÄÈëÃÅÃż÷²»¸ß£¬³ÌÐòÔ±µÄˮƽ¼°¾ÑéÒ²²Î²î²»Æë£¬Ï൱´óÒ»²¿ ......
×òÌìÎÒ˵£¬ÓÃ×éºÏË÷ÒýÓÅ»¯SQL£¬²¢²»ÊÇ×îÓŵģ¬ÕâÊÇÒòΪÔÚ8ÒڵıíÉÏÃæÓиöµÈ¼ÛµÄÎﻯÊÓͼ£¬Õâ¸öÎﻯÊÓͼ¿ÉÒÔ´úÌæÎÒÔÚ֮ǰÔÚ±íÉÏÃæ½¨Á¢µÄ×éºÏË÷Òý¡£
SQL> explain plan for SELECT distinct * from (select
2 (PROD_9005_GDF_WK_SS_FDIM.PROD_4_NAME),
3 PROD_9005_GDF_WK ......
select * from tt t inner loop join ss s with(nolock) on s.c=t.c
ʹÓà nested join
select * from tt t inner merge join ss s with(nolock) on s.c=t.c
ʹÓà merge join
select * from tt t inner hash join ss s with(nolock) on s.c=t.c
ʹÓà hash jion
&n ......
SQL Server Extended Events£¨ÏÂÃæ¼ò³ÆXEvent£©ÊÇSQL Server 2008ÀïмӵÄʼþ´¦Àíϵͳ£¬ÓÃÀ´È¡´úSQL ServerÔ
ÏȵÄSQL TraceµÄ¸ú×Ù»úÖÆ¡£Ê¼þ´¦Àíϵͳ¶ÔÒ»¸ö¸´ÔÓ·þÎñÆ÷ϵͳµÄÅÅ´í£¬µ÷ÊÔÊǼ«Îª¹Ø¼üµÄ¡£ºÍSQL ServerÔÀ´µÄÊÂ
¼þ´¦ÀíϵͳÏà±È½Ï£¬XEvent¾ßÓÐÏÂÁеÄÓÅÊÆ£º
¡¡¡¡ÏûºÄ¸üÉÙµÄϵͳ×ÊÔ´£¬¸üÊÊÓÃÓÚÔÚ²úÆ··þÎñÆ÷É쵀 ......