SQL Injection
Presenter : Pham Nhat Anh
What is This ?
And How to Denfend ?
!"
#
$%&'$%
()***)
+*!",-).,")(
// 0("
*+
"),)) (,1""
*!!"))
!+
$)!,,""%"*
(*22"*
7*!"
()*! "(* 2(*
(*7271)"()("" ,<
5
&*<>?!2"5
<
5
@"A<
"B(* )*C>>?!2"88>
! C>>?
A"C/"B(* )*C>/D*D/>
! C>/D! D/>/?
2+
'0"
)!<GG"")G*+!74CEL%EC'%F$I1
I2M*IKKK88
5
$2""
)!<GG"")G*+!74CE>%EC'%F$I1
I'$*(*23)7!C>&LKK88
5
'"*
H%EC'%F$I1I'$$%EN*O@%="*
3NOCI'$NO@%=23
N*OCH(*M=)HKKK88
,
>?$$%$2"EI"E1"PKF&
I>*PL1LEPQRSLK88
"
>?$@%=$2"E3"EC>*L
88
!
>?%$$2"E88
AUTHENTICATION BYPASS
,
5
&*C>%>LC>
=$X=
(=A*()!!"
!*)*
,A"C/'$B@%=&/D
/3*CJ&*/D
/! CJ /?
A"'****C A"'**IA"1K?
**+*+I/J&*/1
A"2$!+F')K+F"C&*+$7?
**+*+I/J /1
A"2$!+F')K+F"C +$7?
$%%'&
"2"
T'&$!*
A"'****C A"'**I/&M&/1
K?
**+'**$!C'**$!+?
A"'****C A"'**IA"1K?
**+*+I/J&*/1
A"2$!+F')K+F"C&*+$7?
**+*+I/J /1
A"2$!+F')K+F"C +$7?
'"
()**!
)!<GG!!+*(+*G("+!74C2?8?QWEP[[
Y+ Z\@"18'*$"]"",1!1
PWWS
)!<GG +!*,+*G) "+)*"4"CEYRRWPPPE
^+ *=+1"<2F2"*"6(
*1=PWWS
)!<GG +A"2"+*GA"2"+!(