mirror of
https://github.com/hohn/codeql-dataflow-sql-injection.git
synced 2025-12-16 10:13:04 +01:00
26 lines
431 B
Org Mode
26 lines
431 B
Org Mode
* SQL injection example
|
|
** Setup and sample run
|
|
#+BEGIN_SRC sh
|
|
./build.sh
|
|
|
|
./admin create-db
|
|
./admin show-db
|
|
|
|
# Add regular user interactively
|
|
./add-user 2>> users.log
|
|
./admin show-db
|
|
|
|
# Regular user
|
|
echo "sample user" | ./add-user 2>> users.log
|
|
./admin show-db
|
|
|
|
# Johnny Droptable
|
|
echo "Johnny'); DROP TABLE users; -- " | ./add-user 2>> users.log
|
|
|
|
./admin show-db
|
|
|
|
#+END_SRC
|
|
|
|
|
|
|