You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP Phalcon框架SQL注入测试失败:原因排查及修正咨询

SQL Injection Issue in Phalcon PHP Login Module

Let's break down what's happening here, why your current attempt is failing, and how to approach this properly.

Why Your Injection Attempt Threw an Error

First, let's look at the malformed SQL generated from your input test@test.com' or 1=1:

SELECT [Test\Models\Login].* FROM [TEST\Models\Login] WHERE email='test@test.com' or 1=1 --' LIMIT :APL0:

The syntax error happens for two key reasons:

  1. You closed the initial single quote with ', added or 1=1, but the original query still has a trailing single quote from the hardcoded "email='$email'" string.
  2. Even though you tried using -- to comment out that trailing quote, you didn't include a space after --. MySQL requires a space after -- to recognize it as a comment marker—without it, --' gets treated as part of the query string, which breaks parsing when Phalcon adds its automatic LIMIT clause.

Does This Code Have Injection Protection?

No, this code does NOT have proper SQL injection protection. The error you're seeing is just a syntax mistake in your injection attempt, not a security feature. The code directly concatenates user input ($email) into the SQL string, which is a classic insecure practice that leaves it wide open to injection attacks.

How to Fix Your Injection Attempt

To create a valid injection that bypasses the email check, use one of these inputs in the email field:

  1. Bypass the email check (requires valid password for the returned user)

    test@test.com' OR 1=1 -- 
    

    (Note the space after --—this properly comments out the trailing single quote and Phalcon's LIMIT clause. The OR 1=1 makes the WHERE condition always true, so the query returns the first user record in the table.)

  2. Target a specific user (e.g., an admin account)
    If you suspect an admin email exists (like admin@test.com), use:

    admin@test.com' -- 
    

    This will return the admin's record directly, and you can attempt to log in with their password (or further manipulate the query to bypass password checks).

  3. Bypass both email and password checks (advanced)
    To skip password validation entirely, craft an injection that returns a record with a known password hash. For example, the SHA1 hash of an empty password is da39a3ee5e6b4b0d3255bfef95601890afd80709—use this input:

    ' UNION SELECT 1, 'fake@test.com', 'da39a3ee5e6b4b0d3255bfef95601890afd80709' -- 
    

    (Adjust the column count/order to match your Login table's structure. Then enter an empty password in the password field—its SHA1 hash will match the injected value.)

The Secure Fix for the Phalcon Code

To eliminate injection risks entirely, use Phalcon's built-in parameter binding instead of string concatenation. Modify the verifyLogin method like this:

public function verifyLogin ($email, $password) {
    $records = $this->findFirst([
        "email = :email:",
        "bind" => ["email" => $email]
    ]);
    if ($records && sha1($password) == $records->password) {
        return $records->id;
    }
    return false;
}

Parameter binding ensures user input is properly escaped, making SQL injection impossible.

内容的提问来源于stack exchange,提问作者alcantula

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:36:29