FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

:new:新增对于 OWASP TOP10 2017 的代码审计项目之 SQL 注入 · to016/JavaSecurityLearning@22560e2 · GitHub

Repository navigation

Commit 22560e2

Browse files
committed
🆕新增对于 OWASP TOP10 2017 的代码审计项目之 SQL 注入
1 parent 68766b2 commit 22560e2

14 files changed

Lines changed: 262 additions & 85 deletions

File tree

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<project xmlns="http://maven.apache.org/POM/4.0.0"
3+
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
4+
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
5+
<parent>
6+
<artifactId>JavaSec-Code</artifactId>
7+
<groupId>com.drunkbaby</groupId>
8+
<version>0.0.1-SNAPSHOT</version>
9+
</parent>
10+
<modelVersion>4.0.0</modelVersion>
11+
12+
<artifactId>MybatisPluSqli</artifactId>
13+
14+
<properties>
15+
<maven.compiler.source>8</maven.compiler.source>
16+
<maven.compiler.target>8</maven.compiler.target>
17+
</properties>
18+
19+
</project>

JavaSecurity/OWASP TOP10/2017/JavaSec-Code/src/main/java/com/drunkbaby/JavaSecCodeApplication.java renamed to JavaSecurity/OWASP TOP10/2017/JavaSec-Code/MybatisPluSqli/src/main/java/com/drunkbaby/MybatisPluSqliApplication.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@
66

77
@SpringBootApplication
88
@MapperScan("com.drunkbaby.mapper")
9-
public class JavaSecCodeApplication {
9+
public class MybatisPluSqliApplication {
1010

1111
public static void main(String[] args) {
12-
SpringApplication.run(JavaSecCodeApplication.class, args);
12+
SpringApplication.run(MybatisPluSqliApplication.class, args);
1313
}
1414

1515
}
Lines changed: 169 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,169 @@
1+
package com.drunkbaby.controller;
2+
3+
4+
import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper;
5+
import com.drunkbaby.mapper.EmployeeMapper;
6+
import com.drunkbaby.pojo.Employee;
7+
import org.slf4j.Logger;
8+
import org.slf4j.LoggerFactory;
9+
import org.springframework.beans.factory.annotation.Autowired;
10+
import org.springframework.web.bind.annotation.RequestMapping;
11+
import org.springframework.web.bind.annotation.RequestParam;
12+
import org.springframework.web.bind.annotation.RestController;
13+
14+
import java.util.List;
15+
16+
@RestController
17+
public class SQLI {
18+
19+
@Autowired
20+
private EmployeeMapper employeeMapper;
21+
22+
private static Logger logger = LoggerFactory.getLogger(SQLI.class);
23+
24+
@RequestMapping("/mybatis_plus/test")
25+
public Employee test(@RequestParam("name") String name) {
26+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
27+
wrapper.eq("name",name);
28+
Employee employee = employeeMapper.selectOne(wrapper);
29+
return employee;
30+
}
31+
32+
/**
33+
* http://localhost:8081/mybatis_plus/mpVuln01?name=drunkbaby&id=1%20and%20extractvalue(1,concat(0x7e,(select%20database()),0x7e))
34+
* @param name
35+
* @param id
36+
* @return
37+
* 实际的 apply 开发应用中的 SQL 注入
38+
*/
39+
40+
@RequestMapping("/mybatis_plus/mpVuln01")
41+
public Employee mpVuln01(String name, String id) {
42+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
43+
wrapper.eq("name",name).apply("id="+id);
44+
Employee employee = employeeMapper.selectOne(wrapper);
45+
return employee;
46+
}
47+
48+
/**
49+
* http://localhost:8081/mybatis_plus/mpVuln02?id=1%20or%201=1
50+
* @param id
51+
* @return
52+
* 理想情况的 apply 关键字拼接导致的 SQL 注入
53+
*/
54+
55+
@RequestMapping("/mybatis_plus/mpVuln02")
56+
public List<Employee> mpVuln02( String id) {
57+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
58+
wrapper.apply("id="+id);
59+
return employeeMapper.selectList(wrapper);
60+
}
61+
62+
/**
63+
* http://localhost:8081/mybatis_plus/mpVuln03?id=1%20or%201=1
64+
* @param id
65+
* @return
66+
* last 关键字导致的 SQL 注入
67+
*/
68+
69+
@RequestMapping("/mybatis_plus/mpVuln03")
70+
public List<Employee> mpVuln03( String id) {
71+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
72+
wrapper.last("order by " + id);
73+
return employeeMapper.selectList(wrapper);
74+
}
75+
76+
/**
77+
* http://localhost:8081/mybatis_plus/mpVuln04?id=1%20or%201=1
78+
* @param id
79+
* @return
80+
* exists 关键字导致的 SQL 注入
81+
*/
82+
83+
@RequestMapping("/mybatis_plus/mpVuln04")
84+
public List<Employee> mpVuln04( String id) {
85+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
86+
wrapper.exists("select * from employees where id = " + id);
87+
return employeeMapper.selectList(wrapper);
88+
}
89+
90+
/**
91+
* http://localhost:8081/mybatis_plus/mpVuln05?id=1%20or%201=1
92+
* @param id
93+
* @return
94+
* notExists 关键字导致的 SQL 注入
95+
*/
96+
97+
@RequestMapping("/mybatis_plus/mpVuln05")
98+
public List<Employee> mpVuln05( String id) {
99+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
100+
wrapper.notExists("select * from employees where id = " + id);
101+
return employeeMapper.selectList(wrapper);
102+
}
103+
104+
/**
105+
* http://localhost:8081/mybatis_plus/mpVuln06?id=1%20or%201=1
106+
* @param id
107+
* @return
108+
* having 关键字的 SQL 注入
109+
*/
110+
111+
@RequestMapping("/mybatis_plus/mpVuln06")
112+
public List<Employee> mpVuln06( String id) {
113+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
114+
wrapper.notExists("select * from employees where id = " + id);
115+
return employeeMapper.selectList(wrapper);
116+
}
117+
118+
/**
119+
* http://localhost:8081/mybatis_plus/orderby01?id=1%20or%201=1
120+
* @param id
121+
* @return
122+
*/
123+
124+
@RequestMapping("/mybatis_plus/orderby01")
125+
public List<Employee> orderby01( String id) {
126+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
127+
wrapper.notExists("select * from employees where id = " + id);
128+
return employeeMapper.selectList(wrapper);
129+
}
130+
131+
/**
132+
* http://localhost:8081/mybatis_plus/orderby02?id=1%20or%201=1
133+
* @param id
134+
* @return
135+
*/
136+
137+
@RequestMapping("/mybatis_plus/orderby02")
138+
public List<Employee> orderby02( String id) {
139+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
140+
wrapper.notExists("select * from employees where id = " + id);
141+
return employeeMapper.selectList(wrapper);
142+
}
143+
144+
/**
145+
* http://localhost:8081/mybatis_plus/orderby03?id=1%20or%201=1
146+
* @param id
147+
* @return
148+
*/
149+
150+
@RequestMapping("/mybatis_plus/orderby03")
151+
public List<Employee> orderby03( String id) {
152+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
153+
wrapper.notExists("select * from employees where id = " + id);
154+
return employeeMapper.selectList(wrapper);
155+
}
156+
157+
/**
158+
* http://localhost:8081/mybatis_plus/mpSec02?id=1%20or%201=1
159+
* @param id
160+
* @return
161+
*/
162+
163+
@RequestMapping("/mybatis_plus/mpSec02")
164+
public List<Employee> mpSec02( String id) {
165+
QueryWrapper<Employee> wrapper = new QueryWrapper<>();
166+
wrapper.apply("id={0}",id);
167+
return employeeMapper.selectList(wrapper);
168+
}
169+
}

JavaSecurity/OWASP TOP10/2017/JavaSec-Code/src/main/java/com/drunkbaby/mapper/EmployeeMapper.java renamed to JavaSecurity/OWASP TOP10/2017/JavaSec-Code/MybatisPluSqli/src/main/java/com/drunkbaby/mapper/EmployeeMapper.java

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,4 @@
1111

1212
@Repository
1313
public interface EmployeeMapper extends BaseMapper<Employee> {
14-
15-
List<Employee> selectByName(@Param("name") String name);
1614
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
package com.drunkbaby.pojo;
2+
3+
import com.baomidou.mybatisplus.annotation.TableName;
4+
5+
@TableName("employees")
6+
public class Employee {
7+
8+
private Integer id;
9+
private String name;
10+
private String work;
11+
12+
public Integer getId() {
13+
return id;
14+
}
15+
16+
public void setId(Integer id) {
17+
this.id = id;
18+
}
19+
20+
public String getName() {
21+
return name;
22+
}
23+
24+
public void setName(String name) {
25+
this.name = name;
26+
}
27+
28+
public String getWork() {
29+
return work;
30+
}
31+
32+
public void setWork(String work) {
33+
this.work = work;
34+
}
35+
}

JavaSecurity/OWASP TOP10/2017/JavaSec-Code/src/main/resources/application.properties renamed to JavaSecurity/OWASP TOP10/2017/JavaSec-Code/MybatisPluSqli/src/main/resources/application.properties

File renamed without changes.
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd">
3+
4+
<mapper namespace="org.joychou.mapper.UserMapper">
5+
6+
<resultMap type="com.drunkbaby.pojo.Employee" id="Employee">
7+
<id column="id" property="id" javaType="java.lang.Integer" jdbcType="NUMERIC"/>
8+
<id column="name" property="username" javaType="java.lang.String" jdbcType="VARCHAR"/>
9+
<id column="work" property="password" javaType="java.lang.String" jdbcType="VARCHAR"/>
10+
</resultMap>
11+
12+
</mapper>
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
CREATE TABLE IF NOT EXISTS `mp_test`(
2+
`id` INT UNSIGNED AUTO_INCREMENT,
3+
`name` VARCHAR(255) NOT NULL,
4+
`work` VARCHAR(255) NOT NULL,
5+
PRIMARY KEY (`id`)
6+
)ENGINE=InnoDB DEFAULT CHARSET=utf8;
7+
INSERT INTO `employees` VALUES (1, 'drunkbaby', 'eat');
8+
INSERT INTO `employees` VALUES (2, 'dll', 'love');

‎JavaSecurity/OWASP TOP10/2017/JavaSec-Code/pom.xml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@
22
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
33
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
44
<modelVersion>4.0.0</modelVersion>
5+
<packaging>pom</packaging>
6+
<modules>
7+
<module>MybatisPluSqli</module>
8+
</modules>
59
<parent>
610
<groupId>org.springframework.boot</groupId>
711
<artifactId>spring-boot-starter-parent</artifactId>
@@ -43,13 +47,26 @@
4347
<artifactId>mybatis-plus-boot-starter</artifactId>
4448
<version>3.4.0</version>
4549
</dependency>
50+
4651
<!--mybatisplusextension, mybatispluscore-->
4752
<dependency>
4853
<groupId>com.baomidou</groupId>
4954
<artifactId>mybatis-plus-extension</artifactId>
5055
<version>3.4.0</version>
5156
</dependency>
5257

58+
<dependency>
59+
<groupId>org.apache.logging.log4j</groupId>
60+
<artifactId>log4j-core</artifactId>
61+
<version>2.9.1</version>
62+
</dependency>
63+
64+
<dependency>
65+
<groupId>org.apache.logging.log4j</groupId>
66+
<artifactId>log4j-api</artifactId>
67+
<version>2.9.1</version>
68+
</dependency>
69+
5370
</dependencies>
5471

5572
<build>

‎JavaSecurity/OWASP TOP10/2017/JavaSec-Code/src/main/java/com/drunkbaby/controller/EmployeeController.java‎

Lines changed: 0 additions & 28 deletions
This file was deleted.

0 commit comments

Comments
 (0)

Back | FazBrowse Home | New Git URL