SQL Injection
Presenter : Pham Nhat Anh
What is This ?
And How to Denfend ?
!"
#
$%&'$%
()***)
+*!",-).,")(
// 0("
*+
"),)) (,1""
*!!"))
!+
$)!,,""%"*
(*22"*
*!),1 !
"+
3)4
$)!(,*!
&2)
5
2,2
5
!)6
5
7*"!"*
5
'""2"8!
3)94
*:;7,
**
&),)*"(*!!"
!<
5
$77
5
,
5
=!""$=
7*!"
()*! "(* 2(*
(*7271)"()("" ,<
5
&*<>?!2"5
<
5
@"A<
"B(* )*C>>?!2"88>
! C>>?
A"C/"B(* )*C>/D*D/>
! C>/D! D/>/?
2+
'0"
5
'$
,
5
$
5
%
5
$
)2!
5
>%ECE88
**!*
5
5
7
'%@$$-
**!(* )"*
5
F
)!<GG"")G*+!74CEH%EC'%F$I1I'$
JJKK88
5
2*
)!<GG"")G*+!74CEL%EC'%F$I1
I2M*IKKK88
5
$2""
)!<GG"")G*+!74CE>%EC'%F$I1
I'$*(*23)7!C>&LKK88
5
'"*
H%EC'%F$I1I'$$%EN*O@%="*
3NOCI'$NO@%=23
N*OCH(*M=)HKKK88
,
>?$$%$2"EI"E1"PKF&
I>*PL1LEPQRSLK88
"
>?$@%=$2"E3"EC>*L
88
!
>?%$$2"E88
AUTHENTICATION BYPASS
,
5
&*C>%>LC>
C>%>LC>
5
&*C>%ECE88
5
&*C>%>LC>L88
*'*!*
7
5
>?T'*+2+7!M*)"">
U<V!2V V+7L
88
5
>?T'!M* 2
HVVEW+E+E+PV!2"V!+)*"H1
H'$B@%==>88
!
"
!F"
***)I>:?VV9K
!*6=
!
*"*
!
=$X=
(=A*()!!"
!*)*
,A"C/'$B@%=&/D
/3*CJ&*/D
/! CJ /?
A"'****C A"'**IA"1K?
**+*+I/J&*/1
A"2$!+F')K+F"C&*+$7?
**+*+I/J /1
A"2$!+F')K+F"C +$7?
$%%'&
"2"
T'&$!*
A"'****C A"'**I/&M&/1
K?
**+'**$!C'**$!+?
A"'****C A"'**IA"1K?
**+*+I/J&*/1
A"2$!+F')K+F"C&*+$7?
**+*+I/J /1
A"2$!+F')K+F"C +$7?
'"
()**!
!2"* 2!!"
) !,Y1)*2("2"
!*)!"(*PWWE
Z8Z)*!PWW1
7!))0, ""
)(+
$)"(
*!"2A,*,*
!"!!"
L*")
!2"**)"*
!!)
(
E+ $*13"),)1=PWWP
)!<GG +*+*G GSWEY+)*"
P+ @"127*!"1PWWR
)!<GG +7 6+G)!GA"8+)*"
Q+ %""*1:8';
)!<GG +7,+*G!!G%'+!(
R+ =,="
)!<GG +!)!+G*"GG+*,A+!)!
S+ %"H,)
)!<GG +(+G!GGG"GEW,G +EWEG2EWYYQG,"+)
*
+ '7(**1
)!<GG!!+*(+*G("+!74C2?8?QWEP[[
Y+ Z\@"18'*$"]"",1!1
PWWS
)!<GG +!*,+*G) "+)*"4"CEYRRWPPPE
^+ *=+1"<2F2"*"6(
*1=PWWS
)!<GG +A"2"+*GA"2"+!(