chapter 15. security / urban legends
| From: | Dr. Werner Popken | Date: | Tue, 08 Feb 2005 14:05:22 +0000 |
| Subject: | chapter 15. security / urban legends | ||
| Groups: | php.doc | ||
| Request: | Send a blank email to phpdoc+get-969366415@lists.php.net to get a copy of this message | ||
Hello!
the following snippet is taken from
http://de2.php.net/manual/en/security.database.sql-injection.php
SQL Injection
Example 27-2. Splitting the result set into pages ... and making superusers (PostgreSQL and MySQL)
in the German chm:
Beispiel 15-6. Die Ergebnisliste in mehrere Seiten aufsplitten ... und Superuser anlegen (PostgreSQL
and MySQL)
Put this to your MySQL server and you will get
Errno: 1064
Error: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server
version for the right syntax to use near ';
UPDATE user SET Password=PASSWORD('crack') WHERE user='roote
numResults:
query: SELECT id FROM kunde
WHERE 1
AND id = '23951'
ORDER BY 1 limit 0;
UPDATE user SET Password=PASSWORD('crack') WHERE user='roote';
FLUSH PRIVILEGES;
AFAIK, this has never worked.
Regards
Werner Popken
--
Dr. Werner Popken · Herausgeber, Geschäftsführer
ISIS GmbH, Büttendorfer Str.340, 32609 Hüllhorst
Tel +49-5744-5115-74 · Mobil +49-172-93 80 238
------------------------------------------------
Großes Wochenmagazin: http://Pferdezeitung.com
Verkaufspferde: http://Pferdeangebote-online.com
Kleinanzeigen: http://Pferdeanzeigen-online.com
Die Profiplattform http://Pferdemesse-online.com