mirror of
https://github.com/hohn/codeql-dataflow-sql-injection.git
synced 2025-12-16 18:23:05 +01:00
Update the sample run for slide creation
This commit is contained in:
committed by
=Michael Hohn
parent
4c5174bdf5
commit
90a3bee380
16
README.org
16
README.org
@@ -1,8 +1,16 @@
|
||||
* SQL injection example
|
||||
** Setup and sample run
|
||||
#+BEGIN_SRC sh
|
||||
# Use a simple headline prompt
|
||||
PS1='
|
||||
\033[32m---- SQL injection demo ----\[\033[33m\033[0m\]
|
||||
$?:$ '
|
||||
|
||||
|
||||
# Build
|
||||
./build.sh
|
||||
|
||||
# Prepare db
|
||||
./admin create-db
|
||||
./admin show-db
|
||||
|
||||
@@ -10,13 +18,15 @@
|
||||
./add-user 2>> users.log
|
||||
./admin show-db
|
||||
|
||||
# Regular user
|
||||
# Regular user via "external" process
|
||||
echo "sample user" | ./add-user 2>> users.log
|
||||
./admin show-db
|
||||
|
||||
# Johnny Droptable
|
||||
echo "Johnny'); DROP TABLE users; -- " | ./add-user 2>> users.log
|
||||
# Add Johnny Droptable
|
||||
./add-user 2>> users.log
|
||||
Johnny'); DROP TABLE users; --
|
||||
|
||||
# And the problem:
|
||||
./admin show-db
|
||||
|
||||
#+END_SRC
|
||||
|
||||
Reference in New Issue
Block a user