Skip to content · ⁨コンテンツへスキップ⁩

SQL injection · ⁨SQLインジェクション⁩

English

When input becomes a command

  • Many apps build a database query by gluing the user's input into a string. That is dangerous.
  • If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.

日本語

入力がコマンドになる時

  • 多くのアプリは、ユーザーの入力を文字列に貼り付けてデータベースクエリを構築します。これは危険です。
  • アタッカーがSQLを入力としてタイプすると、それがクエリの一部になってしまいます。これがSQLインジェクション — 最も有名なウェブ攻撃です。

悪質な入力 OR 1=1によりWHERE句が常に真となり、すべてのレコードが漏洩する

Log in or create account · ⁨ログインまたはアカウント作成⁩

IGCSE, A-Level & AP