创建SQL注入演示时出现SQL语法错误


sql syntax error while creating a demo for sql injection

我试图创建一个登录页面来演示一个简单的sql注入攻击。下面是从login.html接收输入的php代码:

<?php 
define('DB_HOST', 'localhost'); 
define('DB_NAME', 'sql-injection'); 
define('DB_USER','root'); 
define('DB_PASSWORD',''); 
$con=@mysql_connect(DB_HOST,DB_USER,DB_PASSWORD) or die("Failed to connect to MySQL: " . mysql_error()); 
$db=mysql_select_db(DB_NAME,$con) or die("Failed to connect to MySQL: " . mysql_error()); 
/* $ID = $_POST['user']; $Password = $_POST['pass']; */ 
function SignIn() 
{ 
session_start(); //starting the session for user profile page 
if(!empty($_POST['user']) and !empty($_POST['pass'])) //checking the username and password which is coming from Sign-In.html, are they empty or have some text
 {      
        $query = mysql_query("SELECT * FROM UserName where userName = '$_POST[user]'") or die(mysql_error()); 
        $row = mysql_fetch_array($query) or die(mysql_error()); 
        if(!empty($row['userName']) AND !empty($row['pass'])) 
        { 
                if ($_POST['pass'] == $row['pass'])
                {
                    echo "SUCCESSFULLY LOGIN TO USER PROFILE PAGE...";
                }
                else
                {
                    echo "SORRY... YOU ENTERD WRONG ID AND PASSWORD... PLEASE RETRY..."; 
                }
        } 
        else 
        {   
                    echo "The db is corrupt";
        } 
} 
else{
    echo "The username and password fields cant be empty";
}
} 
if(isset($_POST['submit'])) 
{ 
SignIn(); 
} 
?>

数据库有一个包含列

的表用户名
UsernameID userName   pass
1          mrboolnew  mrbool123

我试图在用户名列中输入这个:

WHERE username ='mrboolnew1';

但是我得到下面的错误:

你的SQL语法有错误;查看与MySQL服务器版本对应的手册,以便在"UPDATE username SET username ='mrboolnew1' WHERE username ='mrboolnew ';"附近使用正确的语法

有人可以帮助我与注入查询。

您已经添加了防止注入攻击的保护,甚至可能不知道。mysql_query()只向数据库发送一个查询(见这里)。不允许使用分号;多个查询也不行。

你必须更努力地注入你自己的代码。