SQL injection · SQL 주입攻击(SQL injection)
When input becomes a command
- Many apps build a database query by gluing the user's input into a string. That is dangerous.
- If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.
입력이 명령어로 변환될 때
- Many apps build a database query by gluing the user's input into a string. That is dangerous.
- If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.
See the attack
- Imagine a login that checks
... WHERE name = '<whatever you typed>'. - An attacker types
' OR '1'='1as the name. The query becomes:
'1'='1'is always true, so the database returns every user. The login is bypassed. Run it and see.
공격 보기
... WHERE name = '<whatever you typed>'를 확인하는 로그인 화면을 상상해 보십시오.- 공격자가
' OR '1'='1를 이름으로 입력합니다.這樣查询 becomes:
SELECT * FROM users WHERE name = '' OR '1'='1';
'1'='1'는 항상 참이므로, 데이터베이스가 모든 사용자를 반환합니다. 로그인이 우회됩니다. 직접 실행해 보세요.
The fix: parameterised queries
- Never glue user input into SQL. Use parameterised queries (also called prepared statements).
- The database treats the input strictly as a value, never as code — so
' OR '1'='1is just a (failed) name to look up. - Also apply least privilege: the web app's database account should only do what it needs.
해결책: 매개변수화 쿼리
- 사용자 입력을 SQL에 절대 붙여 넣지 마십시오. 매개변수화 쿼리(또는 준비된 문법라고도 함)를 사용하십시오.
- 데이터베이스는 입력을 엄격하게 값으로 취급하므로, code로 간주하지 않습니다 — 따라서
' OR '1'='1는 단순히 조회할 (실패한) 이름일 뿐입니다. - 또한 최소 권한 원칙도 적용하십시오. 웹 앱의 데이터베이스 계정에는 필요한 기능만 수행하도록 제한해야 합니다.
Your turn
- Below, write a precise, safe query that returns only bob by his
id. That is the spirit of a parameterised lookup.
Covers: A-Level data security; web application security.
직접 해보기
- 아래에서
id를 통해 bob만 정확하고 안전하게 반환하는 쿼리를 작성하십시오. 이것이 매개변수화 검색의 핵심 개념입니다.
내용: A-Level 데이터 보안; 웹 애플리케이션 보안.
Common mistakes
- Never build a query by joining raw user input into the text.
- Use parameterised queries so input can never change the query.
흔한 실수
- 원본 사용자 입력을 텍스트에 결합하여 쿼리를 구축하지 마십시오.
- 매개변수화 쿼리를 사용하여 입력이 쿼리에 영향을 줄 수 없도록 하십시오.
First, run the attack and see the damage. The app glued the attacker's input into the query, so the condition became name = '' OR '1'='1'. Complete the query exactly like that and see every user leak out. · 먼저 공격을 실행하고 피해를 확인하세요. 앱이 공격자의 입력을 쿼리에 붙였으므로 조건이 name = '' OR '1'='1'이 되었습니다. 쿼리를 정확히 그렇게 완성하여 모든 사용자의 정보가 유출되는 것을 보세요.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.
A safe lookup uses a precise condition. Change the query to return only bob's row, by adding WHERE id = 2. · 안전한 검색은 정확한 조건을 사용합니다. 쿼리를 변경하여 bob의 행만 반환되도록 WHERE id = 2을 추가하세요.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.