9Pythonȫվ֮·ϵÁÐÖ®MySQL SLÊäÈë
·¢²¼Ê±¼ä£º2022-03-19 11:53:08 ËùÊôÀ¸Ä¿£ºÕ¾³¤°Ù¿Æ À´Ô´£º»¥ÁªÍø
µ¼¶Á£ºSQL×¢ÈëÊÇÒ»ÖÖ´úÂë×¢Èë¼¼Êõ£¬¹ýÈ¥³£³£ÓÃÓÚ***Êý¾ÝÇý¶¯ÐÔµÄÓ¦Ó㬱ÈÈ罫¶ñÒâµÄSQL´úÂë×¢Èëµ½ÌØ¶¨×Ö¶ÎÓÃÓÚʵʩ******µÈ¡£ SQL×¢ÈëµÄ³É¹¦±ØÐë½èÖúÓ¦ÓóÌÐòµÄ°²È«Â©¶´£¬ÀýÈçÓû§ÊäÈëûÓо¹ýÕýÈ·µØ¹ýÂË£¨Õë¶ÔÄ³Ð©ÌØ¶¨×Ö·û´®£©»òÕßûÓÐÌØ±ðÇ¿µ÷ÀàÐ͵Äʱºò£¬¶¼ÈÝ
|
SQL×¢ÈëÊÇÒ»ÖÖ´úÂë×¢Èë¼¼Êõ£¬¹ýÈ¥³£³£ÓÃÓÚ***Êý¾ÝÇý¶¯ÐÔµÄÓ¦Ó㬱ÈÈ罫¶ñÒâµÄSQL´úÂë×¢Èëµ½ÌØ¶¨×Ö¶ÎÓÃÓÚʵʩ******µÈ¡£ SQL×¢ÈëµÄ³É¹¦±ØÐë½èÖúÓ¦ÓóÌÐòµÄ°²È«Â©¶´£¬ÀýÈçÓû§ÊäÈëûÓо¹ýÕýÈ·µØ¹ýÂË£¨Õë¶ÔÄ³Ð©ÌØ¶¨×Ö·û´®£©»òÕßûÓÐÌØ±ðÇ¿µ÷ÀàÐ͵Äʱºò£¬¶¼ÈÝÒ×Ôì³ÉÒì³£µØÖ´ÐÐSQLÓï¾ä¡£ SQL×¢ÈëÊÇÍøÕ¾***ÖÐ×î³£ÓõÄ***¼¼Êõ£¬µ«ÊÇÆäʵSQL×¢Èë¿ÉÒÔÓÃÀ´***ËùÓеÄSQLÊý¾Ý¿â¡£ SQL×¢ÈëµÄʵÏÖ ´´½¨SQLdbÊý¾Ý¿â CREATE DATABASE SQLdb; ´´½¨user_info±í CREATE TABLE `user_info` ( `id` int(11) NOT NULL AUTO_INCREMENT, `username` varchar(32) DEFAULT NULL, `password` varchar(32) DEFAULT NULL, PRIMARY KEY (`id`) ) ENGINE=InnoDB DEFAULT CHARSET=utf8; ²åÈëÒ»ÌõÓû§Êý¾Ý ²âÊÔµÄÓû§ÃûÊÇansheng£¬ÃÜÂëas insert into user_info(username,password) values("ansheng","as"); Python´úÂë app.pyÎļþ #!/usr/bin/env python # -*- coding:utf-8 -*- import tornado.ioloop import tornado.web import pymysql class LoginHandler(tornado.web.RequestHandler): def get(self, *args, **kwargs): self.render('login.html') def post(self, *args, **kwargs): username = self.get_argument('username', None) pwd = self.get_argument('pwd', None) conn = pymysql.connect(host='127.0.0.1', port=3306, user='root', passwd='as', db='sqldb') cursor = conn.cursor() temp = "select username from user_info where username='%s' and password = '%s'" %(username, pwd,) effect_row = cursor.execute(temp) result = cursor.fetchone() conn.commit() cursor.close() conn.close() if result: self.write('µÇ¼³É¹¦') else: self.write('µÇ¼ʧ°Ü') application = tornado.web.Application([ (r"/login", LoginHandler), ]) if __name__ == "__main__": application.listen(8888) tornado.ioloop.IOLoop.instance().start() HTML´úÂë login.htmlÓëapp.pyÎļþÔÚͬ¼¶ <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <title>Title</title> </head> <body> <form action="/login" method="post"> <input type="text" name="username" placeholder="Óû§Ãû" /> <input type="text" name="pwd" placeholder="ÃÜÂë" /> <input type="submit" /> </form> </body> </html> ÑÝʾЧ¹û ´ò¿ªä¯ÀÀÆ÷£¬ÊäÈëµØÖ·http://127.0.0.1:8888/login ÌîдÄÚÈÝÈçÏ£º Óû§Ãû£ºasas ' or 1 = 1-- asd ÃÜÂë£ºËæ±ãÌîдһ´®×Öĸ Èçͼ£º 9Pythonȫվ֮·ϵÁÐÖ®MySQL SL×¢Èë µ±µã»÷Ìá½»µÄʱºòÊÇ·ñ»áÌø×ªµ½µÇ½³É¹¦Ò³Ã棿Èç¹ûÄãµÄ´úÂëºÍÎÒÒ»Ñù£¬ÄÇô¾Í»áÌø×ªµ½µÇ½³ÉÒ³Ãæ¡£ Ϊʲô³öÏÖÕâÖÖÎÊÌ⣿ ³öÏÖÕâ¸öÎÊÌâµÄÖ÷ÒªÔÒò¾ÍÊÇÒòΪÎÒÃÇʹÓÃÁË×Ö·û´®Æ´½ÓµÄ·½Ê½À´½øÐÐSQLÖ¸ÁîµÄÆ´½Ó¡£ SQLÖ¸ÁîÆ´½Ó´úÂë temp = "select username from user_info where username='%s' and password = '%s'" %(username, pwd,) ÕâÊÇÒ»¸öÕý³£µÄSQLÆ´½Ó³öÀ´µÄ½á¹û select username from user_info where username='ansheng' and password = 'as' ÕâÊÇÒ»¸ö·ÇÕý³£µÄSQLÆ´½Ó³öÀ´µÄ½á¹û select username from user_info where username='asas' or 1 = 1 -- asd' and password = 's' ´ÏÃ÷µÄÄãÊÇ·ñÒѾ¿´µ½ÆäÖеÄÐþ»úÁËÄØ£¿-- ÈçºÎ·ÀÖ¹£¿ ͨ¹ýPythonµÄpymysqlÄ£¿éÀ´½øÐÐSQLµÄÖ´ÐУ¬ÔÚpymysqlÄ£¿éÄÚ²¿»á×Ô¶¯°Ñ”'“(µ¥ÒýºÅ×öÒ»¸öÌØÊâµÄ´¦Àí£¬À´Ô¤·ÀÉÏÊöµÄ´íÎó ...... effect_row = cursor.execute("select username from user_info where username='%s' and password = '%s'", (username, pwd)) ...... #Pythonȫջ֮· #Sql×¢Èë¡£ £¨±à¼£ºÍøÕ¾¿ª·¢Íø_°²ÑôÕ¾³¤Íø£© ¡¾ÉùÃ÷¡¿±¾Õ¾ÄÚÈݾùÀ´×ÔÍøÂ磬ÆäÏà¹ØÑÔÂÛ½ö´ú±í×÷Õ߸öÈ˹۵㣬²»´ú±í±¾Õ¾Á¢³¡¡£ÈôÎÞÒâÇÖ·¸µ½ÄúµÄȨÀû£¬Ç뼰ʱÓëÁªÏµÕ¾³¤É¾³ýÏà¹ØÄÚÈÝ! |
Ïà¹ØÄÚÈÝ
- ¡¶±¤ÀÝÖ®Ò¹¡·ÏßÏ»Ô⿪·¢ÉÌÆðËß Ã»ÊÚȨÄÚÈÝ»¹¼«²î
- Êý¾Ý¿âÈçºÎʵÏÖ²éѯÄĸö¶ÔÏñÀïÃæ°üº¬Ê²Ã´×ֶεÄsqlÓï¾ä
- ÉúËÀµ×ËÙ£¡Ó¯Í¨G5200±¨³ö¡°688¡±È«³Ç×îµÍ£¡
- СÃ×´û¿îAPP×¢²áÁ÷³ÌÐëÖª
- ºÎСÅô¡°Î¬È¨¡±Êºó̸Ôì³µ£º½øÈëÆû³µÈ¦ºó¾«ÉñѹÁ¦´ó
- MySQLѧϰ֮ÁÙʱ±íÊÇɶ
- ¸ß²ã±Ú¹ÒÌ«ÑôÄÜÔõÑù ¸ß²ã±Ú¹ÒÌ«ÑôÄÜÌØÕ÷½éÉÜ
- Î籨 | Ö§¸¶±¦»¹ÐÅÓÿ¨ÏÂÔ¿ªÊ¼ÊÕ·Ñ £»ÃÀÍÅ·ñÈÏ´óÖÚµãÆÀ½«Ïû
- mysql³öÏÖ1071´íÎóµÄ´¦Ö÷½·¨
- °Ù¶ÈÁªÃËÖеÄÒ»¸ö²»´íµÄͼƬÇл»ÌØÐ§
Õ¾³¤ÍƼö
- Æ´¶à¶à»ØÓ¦É̼ÒάȨһÊ£º¾ùΪÎÊÌâÉÌ¼Ò ¿Û¿îÒÑÈ«
- СÃ×MIX4Ö§³ÖÄÚ´æÀ©Õ¹-¿ÉÒԲ忨Âð
- CentOS6.5¶þ½øÖÆÎļþ°²ÖÃMySQL5.6.39
- ¡¶º£ÔôÍõ¡·¾¢µÐ°¬Äá·µñÏñ ´óÕÐÆë¾ÛЧ¹û³¬°ÔÆø
- ÔÚ´çÍÁ´ç½ðµÄ´ó³ÇÊУ¬ÄãµÄµØÏÂÊÒ¸ü²»Ó¦¸ÃÖ»ÊÇÔÓÎï
- ²©ÊÀXQG70-28468Ï´Ò»úÔõôÑù
- ±ßÚïæä¸Û ¡¶×ÏÈûÇï·ç¡·Ìú±³Óã¿ÍÕ»³¡¾°Ïê½â
- ³ÉǧÉÏÍòµÄÖ¸ÎÆÎļþ±©Â¶ÔÚ²»°²È«µÄÊý¾Ý¿âÖÐ
- PHPÀ¬»ø»ØÊÕ»úÖÆÔõÑùÀí½â£¿ÈçºÎʹÓÃ?
- ¿Æ¼¼ÖúÁ¦£¬ÒËÈË´ûʵÏÖÎÈÔö³¤
ÈȵãÔĶÁ
- mysqlÖ÷´Ó¿½±´ Ò»Ö÷Ò»´Ó
- ÊÕ¼¯Óû§·´À¡ÐÅÏ¢ ×öºÃÍøÕ¾seoÓÅ»¯²ßÂÔ
- ÁªÏëThinkPad E14ÔõôÉèÖÃbiosUÅÌÆô¶¯½øÈëb
- ×öºÃÍøÕ¾ÓÅ»¯·ÖÎöÆÀ¹À£¬²ÅÄÜʵʩ¸ü¼ÑµÄÓªÏú
- MYSQLÐÂÌØÐÔsecure_file_priv¶ÁÈ¡Îļþ
- centos6.5 Ô´Âë°²Éèzabbix3.0.8
- phpÊý×éÖ¸Õ뺯Êý¹¦Äܼ°ÆäÓ÷¨Ê¾Àý
- myisamºÍinnodbµÄ²îÒì
- python´òÓ¡ÈÕÖ¾´úÂëʹÓ÷½·¨½éÉÜ
- ÈÙÒ«magicbook15ÓÐÖ§³ÖÖ¸ÎÆ½âËø¹¦ÄÜÂð

