web安全笔记(一) ----------------------- sql注入

这里写一个简单的sql注入demo

sql_injection.html

<html>
<head>
<meta charset="utf-8">
<title>sql注入</title>
</head>
<body>
<h1>sql注入</h1>
<form action="sql_injection.php" method="post" >
    
    <input type="text" name="name" id="name"><br>
    <input type="submit" name="submit" value="提交">
</form>

</body>
</html>

sql_injection.php

<?php
	include_once 'sql_connect.php';
	

	$name = $_POST['name'];  // 1' OR name = 'gpy  //name =1时无数据//sql注入
	echo $name;
	
	$query  = "SELECT * FROM user  WHERE name = '$name' ";
	$result = $conn  ->query($query);	
	//$rows   = $result->fetch_array(); //返回一行数据
	while ($rows = $result->fetch_array()) {
    
    
		var_dump($rows);
		echo PHP_EOL;
	}
	
?>

猜你喜欢

转载自blog.csdn.net/qq_33253054/article/details/108044397