|
忙碌,但不盲目
SQL注入測(cè)試用例上一篇 / 下一篇 2012-10-08 16:38:19 / 個(gè)人分類:項(xiàng)目技能總結(jié) 1. 1. Drop
table. Guess table name and drop it, note the next flowing SQL language
2. 2. If a field only allow number, give it a String or others 3. Use ‘OR 1=1’, get all records in query function
4. 3. In
login function, give user name field like ‘username’--’, “--’ and A.password = ‘’” is commented
5. 4. Adding
records function, if there is 4 fields in this table, add 5 fields, eg.
6. 5. Input test data in or out of this field data 7. 6. Add
single quotation marks and semicolon, and break off string splicing, this is
similar with point 4
Yellow partis test data we input |
|
|