美文网首页
JDBC_Sql_injection sql注入

JDBC_Sql_injection sql注入

作者: 勇者与王者 | 来源:发表于2019-10-03 00:01 被阅读0次

package Java_JDBC;

import java.sql.*;
import java.util.Scanner;


/**
 *
 * SQl注入攻击
 */
public class JDBC_Sql_injection {
    public static void main(String[] args) throws ClassNotFoundException, SQLException {
        Class.forName("com.mysql.jdbc.Driver");
        String url = "jdbc:mysql://192.168.8.14:3306/day22_JDBC";
        String user = "root";
        String password = "123456";
        Connection con = DriverManager.getConnection(url,user,password);
        Statement st = con.createStatement();

        Scanner sc = new Scanner(System.in);
        String username = sc.nextLine();
        String passwd = sc.nextLine();

        String sql = " select * from users where username='"+username+"' and PASSWORD='"+passwd+"'";
        System.out.println(sql);

        ResultSet rs = st.executeQuery(sql);
//        System.out.println(rs.next());

        while (rs.next()){
            System.out.println(rs.getString("username")+ "   "+rs.getString("PASSWORD"));
        }

        rs.close();
        st.close();
        con.close();


    }
}

相关文章

网友评论

      本文标题:JDBC_Sql_injection sql注入

      本文链接:https://www.haomeiwen.com/subject/sdarpctx.html