Home > ³Ì·s®ø®§
±Æª©¥Î¹Ï¥Ü
* Mass SQL Injectiong¤âªk¦hÅÜ

¹ï©ó»í¦ë¬ì§Þ±M®×,»í¦ë¬ì§Þ±M®×¤H­û¤£Â_ª`·Nªº¥Ø«eªº§ðÀ»¤âªk§YÅܤÆ,§Æ±æ±N¨C­Ó±M®×³£»s§@ªº§ó§¹¬ü¤Î¦w¥þ.

¥H¤U¬°·s»D¥þ¤å:

5¤ë¥÷Àb«È§Q¥ÎMass SQL Injection¤âªk¡A¥H¾÷¾¹¤Hµ{¦¡µo°Ê¤j¶q§ðÀ»¡A¤£¶È§ð³´¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡Aªñ´Á¤S¦A§Q¥ÎFlash¼½©ñ¾¹ªºº|¬}¡Aµo°Ê²Ä¤Gªi°w¹ï¨Ï¥ÎªÌ¹q¸£ªº§ðÀ»¡C­×¥¿·½½X©MWebÀ³¥Îµ{¦¡¨¾¤õÀð¡A¬O¥D­nÀ³Åܤ§¹D¡C

¦b5¤ë¤¤¡A»OÆW¦³³\¦hºô¯¸¾D¨ü¤FÃz¶qªºMass SQL Injection§ðÀ»¡Aªì¨B¦ô­p¦³¶W¹L10¸U»O¹q¸£¨ü®`¡C¦bµuµu¤£¨ì1©Pªº®É¶¡¡A¦P¼Ë¤@§åÀb«È¡A¤S§Q¥ÎAdobe Flash¼½©ñ¾¹ªºº|¬}¡A¦A«×µo°Ê§ðÀ»¡C

¸ê¦w±M®aªí¥Ü¡A±q³o´XªiÀb«Èªº§ðÀ»¤âªk¥i¥Hµo²{¡A³o¤@§åÀb«È¡A¨ä¹ê¬O¦b´ú¸Õ¾ã­ÓMass SQL Injection§ðÀ»ªº®Ä²v»P¦¨®Ä¡CÀb«Èªº¥Øªº¨ä¹ê¬O­n§ä¨ì¦n¥Îªº§ðÀ»¤âªk¡A¦b§óµuªº®É¶¡¤º±±¨î§ó¦h¹q¸£¡A¶i¦ÓÅѨú¹q¸£ªº¸ê®Æ¡C

¥H¾÷¾¹¤Hµ{¦¡µo°Ê¤j¶qSQL Injection§ðÀ»
4¤ë©³¡A¼Ú¬ü¦a°Ï´Nµo²{¤j¶qªºMass SQL Injection§ðÀ»¤âªk¡C5¤ë¤¤¡A¸ê¦w¤½¥qªü½X¬ì§Þªº¬ã¨s¤H­û¡A±q¦w¸Ë¦b¥ø·~ºÝªººô¸ôÀ³¥Îµ{¦¡¨¾¤õÀð¡]WAF¡^¡Aµo²{³oºØ§ðÀ»¤w¸gªi¤Î»OÆW¡A¥L­Ì¶i¤@¨B¤ÀªRµo²{¡A³æ´N5¤ë16¤é¤@¤Ñ¡A¦Ü¤Ö´N¦³1¸U­Óºô¯¸³Q³o­Ó§ðÀ»¤âªk´Ó¤J´c·Nµ{¦¡¡A¦Ó³Q´Ó¤J´c·N³sµ²ªººô­¶«h°ª¹F10¸U­Ó¡C

Àb«Èªº§ðÀ»¤âªk¡A¬O¥ý§Q¥ÎGoogle·j´M¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A¦A¥HSQL Injection¤âªk¤J«I¡Cªü½X¬ì§Þ¸ê¦wÅU°Ý¤B©Ê¦úªí¥Ü¡AGoogle·j´M¤ÞÀº·|¸T¤î¦P¤@­ÓIP¨Ó·½¦bµu®É¶¡¤º¤j¶q·j´M¡A¤@¥¹¦³Ãþ¦ü¦æ¬°¡AGoogle ·j´M¤ÞÀº´N·|­n¨D¨Ï¥ÎªÌ¿é¤J¹Ï§ÎÅçÃÒ½X¡]CAPTCHAs¡^©Î¸T¤î·j´M¡C¤B©Ê¦ú»¡¡AÀb«È¥i¥H¤j¶q§Q¥ÎGoogle·j´M¡A¥i¯à¬O¨Æ¥ý´x±±¤F¤j¶qªº³ÈÀw¹q¸£¡A°µ¨ì¥H¦Û°Ê¤Æµ{¦¡¤j¶q·j´M¦³SQL º|¬}ªººô¯¸¡A¨Ãµo°Ê§ðÀ»¡C

Àb«È¥ÎFlashº|¬} ´ú¸Õ§ðÀ»¤âªkºë·Ç«×
²Ä¤@ªiªºMass SQL Injection§ðÀ»¥D­n¬O°w¹ïºô¯¸¦øªA¾¹¡A§ðÀ»ºÝªºIP¨Ó·½¥X¦Û¤¤°ê¤j³°¡C´°¶§¬ì§Þ¸ê²`¸ê¦w§Þ³NÅU°Ý·¨§BÃvªí¥Ü¡A¦b²Ä¤@ªi§ðÀ»¤¤³Q´Ó¤J´c·Nµ{¦¡ªººô¯¸¦øªA¾¹¡A³QÀb«È§Q¥Î¨Óµo°Ê²Ä¤Gªi§ðÀ»¡AÀb«ÈÂê©w¤@¯ë¨Ï¥ÎªÌ¹q¸£Flash¼½©ñ¾¹ªºº|¬}¡A¥u­nÂsÄý³o¨Ç¨üÀbºô¯¸ªº¹q¸£¡A¨S¦³­×¸ÉFlashµ{¦¡ªºº|¬}¡A¨º»ò´c·Nµ{¦¡´N¦³¥i¯à¤J«I¦¨¥\¡A¶i¦Ó±±¨î¹q¸£¡C

¼ÆÁp¸ê¦w¬ãµo³B°ÆÁ`¸g²z±i¸Î±Óªí¥Ü¡A¡u³o¤@ªiAdobe Flashªº§ðÀ»¤¤¡A¦b5¤ë30¤é­â±á¹sÂI¹s¤À´NºI¤î¡A¬O¤@­Ó¦³®É®Ä©Êªº§ðÀ»¤âªk¡A¡v

±i¸Î±Ó±À´ú¡A¥Ø«e¬Ý¨ÓÀb«È¬O¦b´ú¸Õ§ðÀ»¤âªkªº¦¨®Ä»Pºë·Ç«×¡C·íÀb«È¦¨¥\ÅçÃÒ¤F¥HGoogle Hacking·f°tMass SQL Injection¤âªk¡A¥i¥H¦bµu®É¶¡¤º§ð³´¤j¶qºô¯¸¦øªA¾¹¡A¶i¦Ó±±¨î§ó¦hÂsÄýºô¯¸ªº¹q¸£¤§«á¡A¤]´N·N¨ýµÛ¡A³o§åÀb«È¹ï¨ü®`¹q¸£ªº´x´¤«×¤w¸g¨ì¡u¦p¤JµL¤H¤§¹Ò¡vªº¦a¨B¡C

±µ¤U¨Ó¡AÀb«È´N¥i¥H¦b¨ü®`¹q¸£¤j¶q¦w¸Ë»»±±ªº¾÷¾¹¤Hµ{¦¡¡A°£¤F¥i¥H§Q¥Î³o¨Ç³ÈÀw¹q¸£µo°ÊDDoS§ðÀ»¡]¤À´²¦¡ªýÂ_¦¡§ðÀ»¡^¡A§ó¥i¥H¶X¾÷ÅѨú¡B³c°â¹q¸£ùتº­Ó¤H»P¥ø·~¾÷±K¸ê®Æ¸ê®Æ¹Ï§Q¡C

ÂùºÞ»ô¤U ¸Ñ¨MSQL Injection¦Ñ°ÝÃD
»OÆW¥ø·~¹ï©óSQL Injection§ðÀ»¤âªk¡A¸g±`³B©ó§ô¤âµLµ¦ªºª¬ºA¡A·¨§BÃvªí¥Ü¡A¦h¼Æ¤H³£©ê«ù¡u¥H©ì«ÝÅÜ¡vªº¤ßºA¡A¥u­n­Ó¤H©Î¤½¥q¨S¨ü®`¡B¨S¨£³ø´N¦n¡C³o¼Ëªºª¬ªp¤£§ïÅÜ¡ASQL Injectionªº°ÝÃD´N·|Ä~Äò¦s¦b¡C

­±¹ïSQL Injection§ðÀ»ªº´c©Ê´`Àô¡A´°¶§¬ì§Þ§Þ³NÅU°Ý¼B«T¶¯»{¬°¡A¤@©w±o¦hºÞ»ô¤U¤~¦³¾÷·|®Úµ´¡A¥L»¡¡A¥¿¥»²M·½¤§¹D¬O­×§ï­ì©l½X¡A¥]¬A·½½XÀË´ú¡]Code Review¡^¡Bºô¯¸±½´y¡]Web Scan¡^¥H¤Îº¯³z´ú¸Õ¡]Penetration Testing¡^µ¥¤è¦¡¡C

­YµLªk§Y¤Î­×§ï­ì©l½X¡A«h¥i§Q¥ÎWebÀ³¥Îµ{¦¡¨¾¤õÀð¡]WAF¡^§@¬°¨¾¿m¡BÀ³«æ¤§¥Î¡C¤å¡ó¶À«Û´Ù

­°§CSQL Injection§ðÀ»ªº3¤jÃöÁä
¸ê²`ªº¸ê¦w¬ã¨s­û¼ÆÁp¸ê¦w¬ãµo³B°ÆÁ`¸g²z±i¸Î±Óªí¥Ü¡A»OÆW¥ø·~¨Ï¥Î·L³n.NET¥­»O¤ñ¨Ò«Ü°ª¡A­Y¯à´x´¤ASP .NET¨¾¿mSQL Injectionªº3¤jÃöÁä¡A±N¦³§U©ó­°§C³oÃþ§ðÀ»¡C

iThome°Ý¡G¦p¦ó¦³®Ä¨¾°ôSQL Injectionªº§ðÀ»¡H
±i¸Î±Óµª¡G·L³n°w¹ïASP .NET¥­»O±À¥X³\¦h¦w¥þ¤å¥ó¡A±Ð¾É¶}µo¤H­û°µ¦UºØ¦w¥þ°Ñ¼Æ³]©w¡C¥Ø«e¥i¥H±qµ{¦¡¶}µo¡B»P¸ê®Æ®wµ{¦¡ªº³sµ²¥H¤ÎIIS 5.0¦øªA¾¹ªº³]©wµ¥3¤è­±µÛ¤â¶i¦æ¡C

°Ý¡G¶}µoASP .NET¸Óª`·N­þ¨Ç°Ñ¼Æªº³]©w¡H
µª¡G¦bASP .NET¥­»O¡A·L³n¤]´£¨Ñ¦UºØWeb UI¤¸¥ó¨Ñ¶}µo¤H­û¿ï¾Ü¡C³z¹L³]©w³o¨ÇWeb UI¤¸¥ó¡A¯à°÷À°¶}µo¤H­û¦b¶i¦æ¦UºØ¯S®í²Å¸¹¹LÂo¡B¥¿³W¤Æªí¥Ü¦¡¡]Regular Expression¡^¡A¬Æ¦Ü¬O¶Â¡B¥Õ¦W³æµ¥³]©w¡A³£¦³¤@¨Ç°Ñ¼Æ¥i¥H¤Ä¿ï¡AÁ×§K¥H«e°µASP¶}µo®É¡A©Ò¦³°Ñ¼Æ¥\¯à³£¥²¶·¦Û¤v¼g¡A¦Ó±`±`·|¥X²{±¾¤@º|¸Uªº²{¶H¡C

°Ý¡Gµ{¦¡»P«áºÝ¸ê®Æ®wªº³sµ²¤W¡A»Ý­nª`·N¤°»ò¡H
µª¡GSQL Injection¥D­nµo¥Í­ì¦]¦b©ó¡A«eºÝ¨t²Î¥á¥XªºSQL¬d¸ß»yªk¤£°®²b©Î¦³¿ù»~¡A¾É­P«áºÝ¦øªA¾¹°µ¤F¤£·íªº¤ÏÀ³¡C³\¦h¶}µo¤H­û¥H©¹²ßºDª½±µ³z¹LSQL »yªk¥h¬d¸ß«áºÝ¸ê®Æ®w³sµ²¡C¤ñ¸û¦nªº§@ªk«h¬O¡AÅý«eºÝSQL»yªk©Î«ü¥O¡A³z¹L°Ñ¼Æ¤Æµ{§Çªº©I¥s¤è¦¡¡A¦s¨ú«áºÝªº¸ê®Æ®w¡C¤@¥¹«eºÝSQL»yªk¤º§t´c·N²Å¸¹®É¡A«áºÝ¸ê®Æ®w´N¤£·|°µ¥ô¦ó¯S®í¤ÏÀ³¡C

°Ý¡Gºô¯¸¦øªA¾¹»Ý­nª`·N¤°»ò©O¡H
µª¡G³\¦hASP .NETªº¥ø·~¥Î¤á¡A¤]³£±Ä¥Î·L³nIIS 5.0ºô¸ô¦øªA¾¹¡C¦bIIS¦øªA¾¹ºÝªº³]©w¡A¥D­n¯S§O°w¹ïWeb Config³]©wÀɰµ°Ñ¼Æ³]©w¡C³o¼Ëªº°Ñ¼Æ³]©w±qCookie¡BView_State_¨ì»{ÃÒµ¥¡A«e«á¶W¹L100¦h¶µ³]©w¡C³o¨Ç°Ñ¼Æ³]±o¦n¡A´N¥i¥H´£°ª Web Serverªº¦w¥þ©Ê¡C

°Ý¡G¤°»ò¬O¤ñ¸û¬Ù¤OªºIIS¦øªA¾¹³]©w¤è¦¡¡H
µª¡G³o­Ó¬Ù¤Oªº³]©w¡A¥D­n¬O¥Ñ¤¤°ê¤j³°¦h¤H¦@¦P¶}µo¥X¨Óªº¡u³q¥Îª`¤J¹LÂo¾¹¡v¡C³o¬O¤@­Ó°ò©óIIS¨t²Îªº¼Ò²Õ¡A®Ö¤ß¥ÑC++¼¶¼g¡C¥u­n±N¸Óµ{¦¡¦w¸Ë¦bIIS¦øªA¾¹¤W¡A´N¥i¥H«OÅ@¾ã­Ó¨t²ÎÀɮסA¹w¨¾³Q¤H§Q¥ÎASPµ{¦¡º|¬}¡A¶i¦Ó³Qª`¤J´c·N»yªk¡A¤]¥i¥H¨¾¤î¸ê®Æ®w³Q¤U¸ü¡C

¥Ø«e¤¤°ê¤j³°«Ü¦hºô¯¸¡A³£¨Ï¥Î³o¼Ëªº³q¥Îª`¤J¹LÂo¾¹¡A¥H­°§CSQL Injectionªº¨ü®`µ{«×¡C¤å¡ó¶À«Û´Ù

Mass SQL Injection 3¶¥¬q§ðÀ»¤è¦¡

²Ä1¶¥¬q ¥HGoogle Hacking§ä´M¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A´Ó¤J´c·Nµ{¦¡³sµ²
Àb«È³z¹L¦Û°Ê¤Æ¾÷¾¹¤Hµ{¦¡¡A§Q¥ÎGoogle·j´M¤ÞÀº§ä¥X¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A¤j¶q´Ó¤J´c·Nµ{¦¡©Î´c·N³sµ²¡C»OÆW¦ô­p¦Ü¤Ö¦³¶W¹L10¸U»O¹q¸£¨ü®`¡C

²Ä2¶¥¬q ÂǥѳQ¨üÀbªººô¯¸¦øªA¾¹¡A¹ï©óÂsÄýºô¯¸ªº¹q¸£µo°ÊAdobe Flashº|¬}§ðÀ»

Àb«È¬Ý·Ç¤@¯ë¹q¸£¨Ï¥ÎªÌ¤£·|§ó·sAdobe Flashªºº|¬}¡AÂǥѲĤ@ªi¨üÀbªººô¯¸¡A¥h·P¬V§ó¦h³sºôªº¹q¸£¡C¦pªG¹q¸£ªºFlashº|¬}¨S¦³­×¸É¡A´N·|¦¨¬°³QÀb«È´x±±ªº³ÈÀw¹q¸£¡C

²Ä3¶¥¬q ¤U¤@¨B¡G¤j¶q³ÈÀwºô¸ô»P¸ê®Æ¥~¬ª

¤£½×¬O¤j¶qSQL Injection§ðÀ»¡A©ÎªÌ¬O§Q¥ÎAdobe Flashº|¬}µo°Ê§ðÀ»¡A³£¥u¬OÀb«È¦b´ú¸Õ§ðÀ»¦¨®Äªº«e­ï¯¸¦Ó¤w¡C·íÀb«È½T»{§ðÀ»¤âªk¯à¦³®Ä¹F¦¨¥Ø¼Ð«á¡A´N¯à°÷´N¥iµo°ÊDDoS¡]¤À´²¦¡ªýÂ_¦¡§ðÀ»¡^¤ÎÅѨú³c°â¸ê®Æ¡C¤å¡ó¶À«Û´Ù
Âà¸ü:¸ê¦w¤§²´

 
±Æª©¥Î¹Ï¥Ü