APP下载

基于Apache+PHP+Mysql网站SQL注入防护探讨

2017-02-13李俊锋

网络空间安全 2016年12期

【 摘 要 】 随着互联网+时代的到来,中小企业网站雨后春笋,考虑成本和建站周期,一般都是基于Apache+PHP+Mysql架构。越来越多的网络访问通过Web界面进行操作,Web安全已经成为互联网安全的一个热点,基于Web的攻击广为流行,SQL注入、跨站脚本等Web应用层漏洞的存在使得网站沦陷、页面篡改、网页挂马等攻击行为困扰着网站管理者并威胁着网站以及直接用户的安全。论文就SQL注入作一些归纳总结。

【 关键词 】 网站;SQL;注入防护

【 中图分类号 】 TP392

【 文献标识码 】 A

Based on the Apache+PHP+Mysql SQL Injection Site Protection to Discuss

Li Jun-feng

(Zigui County Human Resources and Social Security Information Center HubeiYichang 443600)

【 Abstract 】 With the advent of the era of Internet+, websites of small and medium-sized enterprises sprung up. Considering the cost and build cycle, they are generally based on Apache+PHP+Mysql architecture. More and more network access via a Web interface. Web security has become a focus of the Internet security. Web-based attack is popular.The Existence of The Web application layer holes such as SQL injection and cross-site scripting vulnerabilities has been affecting website managers and threatening the safety of site and direct user.They make website fall, tampered with, Web page hang a horse. Engaged in small and medium-sized website development and construction management for many years, accumulated certain experience,this article will make a few generalizations for SQL injection. For reference only.

【 Keywords 】 website; sql; injection protection

1 引言

SQL注入技术是通过把SQL命令插入到Web表单递交或输入域名或页面请求的查询字符串,提交精心构造的数据库语句,使其反馈一些有用的数据,去欺骗数据库,最终达到欺骗服务器执行恶意的SQL命令。假如只有Web服务器的话,是没法进行的。

2 SQL注入形式

常用的SQL注入手法有两种:一种是猜测,让数据库暴出用户名、密码等信息;另一种直接绕过认证,取得权限。相对应防护,就必须禁止特殊数据的提交或将特殊提交的数据修改。

3 Apache+PHP+Mysql架构网站威胁风险等级

高风险:跨站脚本攻击、拒绝服务。

中风险:内容欺骗、信息泄露、远程信息泄露、资源位置可预测。

其它(应用)风险:安全配置错误、不安全的加密存储、没有限制URL访问、敏感数据泄露、缺乏功能层次的访问控制。

4 常见SQL注入漏洞及防护对策。

4.1 客户端攻击类型

4.1.1 跨站脚本攻击

指利用网站漏洞从用户那里恶意盗取信息。用户在浏览网站、使用即时通讯软件、甚至在阅读电子邮件时,通常会点击其中的链接。……

登录APP查看全文