You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

未做输入sanitizing的PHP登录页面SQL注入无法利用问题咨询

Hey Connor, let's break this down step by step—since you're new to PHP and SQL injection, it's totally normal to hit this roadblock even when you think you're not sanitizing input. Let's walk through why your attempts might be failing, how to test properly, and how to fix the vulnerability for good.

1. Why Your SQL Injection Isn't Working (Common Culprits)

Even if you didn't add explicit input sanitizing, there are hidden factors that could block your injection attempts:

  • You might be using prepared statements without realizing it: If your login code uses mysqli_prepare() or PDO parameter binding (even if you copied it from a tutorial), those automatically neutralize injection attempts by separating SQL logic from user input. Double-check your query code to confirm.
  • Magic Quotes could be enabled (old PHP versions): In PHP versions before 5.4, the magic_quotes_gpc setting automatically escapes single quotes, backslashes, and null characters in user input. This turns your injection string like ' OR 1=1-- into \' OR 1=1--, which breaks the injection. Test this with echo get_magic_quotes_gpc();—if it returns 1, magic quotes are on.
  • You're using the wrong injection syntax: Different databases use different comment characters. For MySQL, you need a space after -- (like -- ) or use # to comment out the rest of the query. If your target field is a string (which usernames/passwords almost always are), you have to properly close the existing single quote in the query.
  • No visible error feedback: If your PHP code suppresses MySQL errors (with @mysqli_query() or error reporting turned off), you might be making syntax mistakes in your injection string without knowing it. Enable error reporting temporarily with error_reporting(E_ALL); ini_set('display_errors', 1); to see what's going wrong.
2. How to Test for SQL Injection Properly

First, confirm your raw query code looks something like this (the unsafe, un-sanitized version):

$username = $_POST['username'];
$password = $_POST['password'];
$query = "SELECT * FROM users WHERE username='$username' AND password='$password'";
$result = mysqli_query($conn, $query);

Then try these test cases:

  • Login bypass test: In the username field, enter ' OR 1=1-- (make sure there's a space after --), and enter any random text in the password field. This transforms the query into:
    SELECT * FROM users WHERE username='' OR 1=1-- ' AND password='randomtext'
    
    The -- comments out the rest of the query, so it becomes SELECT * FROM users WHERE username='' OR 1=1—which will return all users and let you log in.
  • Quote escape test: Enter just a single quote ' in the username field and submit. If you get a MySQL syntax error (like You have an error in your SQL syntax...), that means the quote isn't being escaped, so injection should be possible. If no error appears, something is sanitizing your input behind the scenes.
3. Fixing the SQL Injection Vulnerability

The only reliable way to prevent SQL injection is to use prepared statements with parameter binding—forget about manual sanitization like mysql_real_escape_string() (it's deprecated and error-prone). Here's how to implement it:

For MySQLi:

// Prepare the query with placeholders (?)
$stmt = mysqli_prepare($conn, "SELECT * FROM users WHERE username=? AND password=?");
// Bind parameters: "ss" means two string values (username and password)
mysqli_stmt_bind_param($stmt, "ss", $username, $password);
// Execute the query
mysqli_stmt_execute($stmt);
// Get the result
$result = mysqli_stmt_get_result($stmt);

For PDO (more flexible, database-agnostic):

// Prepare the query
$stmt = $pdo->prepare("SELECT * FROM users WHERE username=? AND password=?");
// Execute with an array of parameters
$stmt->execute([$username, $password]);
// Fetch the user data
$user = $stmt->fetch();

Bonus: Secure Password Storage

While not directly related to SQL injection, you should never store plain-text passwords. Use PHP's built-in password hashing functions:

// When creating a user
$hashedPassword = password_hash($password, PASSWORD_DEFAULT);
// When logging in
if ($user && password_verify($password, $user['password'])) {
    // Login successful
}

内容的提问来源于stack exchange,提问作者Connor J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:14:41