SQL injection.........

OptiplexFx

Member
May 29, 2009
2,568
44
0
cyberspace
Menna eka gana podi wistharayak: SQL Injection-Wikipedia

Basically SQL injection walin pulwan SQL statement ekaka parameters use karala statement eken adahas karala thiyana deyata wada wenath deyak karaganna. Oya Wikipedia article eke example ekak menna :

Hithanna menna me wage statement ekak thiyanawa kiyala
Code:
SELECT * FROM users WHERE name = '" + userName + "';
Api hithamu oya statement eka login page ekakata daala thiyanawa kiyala. Kauruhari valid user kenek valid user name ekak enter kaloth oya query eken not null result ekak return karanna one. Namuth userName kiyana eka wenuwata api
Code:
a' or 't'='t
wage ekak enter kaloth statement eka menna me widihata wenas wenawa
Code:
SELECT * FROM users WHERE name = 'a' OR 't'='t';
Oya statement eken hama welawema records rerun karanawa, mokada hama welawema t=t kiyana eka true wena nisa. Eeh kiyanne boru user kenekuta unath SQL oya SQL statement eka use karala records okkoma retrieve karaganna puluwan. Oya widihata horen samahara SQL statements exploit karana eka thamai SQL injection wala basic idea eka.
 

thilini1990

Member
Nov 15, 2009
304
4
0
ane thankz....... wap site eheka mage profile eka wena kenek ara gaththa.. eya eka kale oken lu..... eka wenna puluwanda?? elakiri eketh ehema karala mage profile eka kawuru hari ganiwidha? :(