Skip to content

SQL injection · ⁨SQL 注入⁩

English

When input becomes a command

  • Many apps build a database query by gluing the user's input into a string. That is dangerous.
  • If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.

中文

当输入变成了命令

  • 许多应用通过把用户输入拼接进一个字符串来构造数据库查询。这很危险。
  • 如果攻击者把 SQL 当作输入来输入,它就可能成为查询的一部分。这就是 SQL 注入 —— 最著名的 Web 攻击。

恶意输入 OR 1=1 让 WHERE 条件永远为真,泄露所有数据行

Log in or create account · ⁨登录或创建账户⁩

IGCSE, A-Level · ⁨IGCSE、A-Level⁩ & AP · ⁨与 AP⁩