| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,19 @@ | |||
| 1 | + <?xml version="1.0" encoding="UTF-8"?> | ||
| 2 | + <project xmlns="http://maven.apache.org/POM/4.0.0" | ||
| 3 | + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | ||
| 4 | + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> | ||
| 5 | + <parent> | ||
| 6 | + <artifactId>JavaSec-Code</artifactId> | ||
| 7 | + <groupId>com.drunkbaby</groupId> | ||
| 8 | + <version>0.0.1-SNAPSHOT</version> | ||
| 9 | + </parent> | ||
| 10 | + <modelVersion>4.0.0</modelVersion> | ||
| 11 | + | ||
| 12 | + <artifactId>MybatisPluSqli</artifactId> | ||
| 13 | + | ||
| 14 | + <properties> | ||
| 15 | + <maven.compiler.source>8</maven.compiler.source> | ||
| 16 | + <maven.compiler.target>8</maven.compiler.target> | ||
| 17 | + </properties> | ||
| 18 | + | ||
| 19 | + </project> | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -6,10 +6,10 @@ | |||
| 6 | 6 | ||
| 7 | 7 | @SpringBootApplication | |
| 8 | 8 | @MapperScan("com.drunkbaby.mapper") | |
| 9 | - public class JavaSecCodeApplication { | ||
| 9 | + public class MybatisPluSqliApplication { | ||
| 10 | 10 | ||
| 11 | 11 | public static void main(String[] args) { | |
| 12 | - SpringApplication.run(JavaSecCodeApplication.class, args); | ||
| 12 | + SpringApplication.run(MybatisPluSqliApplication.class, args); | ||
| 13 | 13 | } | |
| 14 | 14 | ||
| 15 | 15 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,169 @@ | |||
| 1 | + package com.drunkbaby.controller; | ||
| 2 | + | ||
| 3 | + | ||
| 4 | + import com.baomidou.mybatisplus.core.conditions.query.QueryWrapper; | ||
| 5 | + import com.drunkbaby.mapper.EmployeeMapper; | ||
| 6 | + import com.drunkbaby.pojo.Employee; | ||
| 7 | + import org.slf4j.Logger; | ||
| 8 | + import org.slf4j.LoggerFactory; | ||
| 9 | + import org.springframework.beans.factory.annotation.Autowired; | ||
| 10 | + import org.springframework.web.bind.annotation.RequestMapping; | ||
| 11 | + import org.springframework.web.bind.annotation.RequestParam; | ||
| 12 | + import org.springframework.web.bind.annotation.RestController; | ||
| 13 | + | ||
| 14 | + import java.util.List; | ||
| 15 | + | ||
| 16 | + @RestController | ||
| 17 | + public class SQLI { | ||
| 18 | + | ||
| 19 | + @Autowired | ||
| 20 | + private EmployeeMapper employeeMapper; | ||
| 21 | + | ||
| 22 | + private static Logger logger = LoggerFactory.getLogger(SQLI.class); | ||
| 23 | + | ||
| 24 | + @RequestMapping("/mybatis_plus/test") | ||
| 25 | + public Employee test(@RequestParam("name") String name) { | ||
| 26 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 27 | + wrapper.eq("name",name); | ||
| 28 | + Employee employee = employeeMapper.selectOne(wrapper); | ||
| 29 | + return employee; | ||
| 30 | + } | ||
| 31 | + | ||
| 32 | + /** | ||
| 33 | + * http://localhost:8081/mybatis_plus/mpVuln01?name=drunkbaby&id=1%20and%20extractvalue(1,concat(0x7e,(select%20database()),0x7e)) | ||
| 34 | + * @param name | ||
| 35 | + * @param id | ||
| 36 | + * @return | ||
| 37 | + * 实际的 apply 开发应用中的 SQL 注入 | ||
| 38 | + */ | ||
| 39 | + | ||
| 40 | + @RequestMapping("/mybatis_plus/mpVuln01") | ||
| 41 | + public Employee mpVuln01(String name, String id) { | ||
| 42 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 43 | + wrapper.eq("name",name).apply("id="+id); | ||
| 44 | + Employee employee = employeeMapper.selectOne(wrapper); | ||
| 45 | + return employee; | ||
| 46 | + } | ||
| 47 | + | ||
| 48 | + /** | ||
| 49 | + * http://localhost:8081/mybatis_plus/mpVuln02?id=1%20or%201=1 | ||
| 50 | + * @param id | ||
| 51 | + * @return | ||
| 52 | + * 理想情况的 apply 关键字拼接导致的 SQL 注入 | ||
| 53 | + */ | ||
| 54 | + | ||
| 55 | + @RequestMapping("/mybatis_plus/mpVuln02") | ||
| 56 | + public List<Employee> mpVuln02( String id) { | ||
| 57 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 58 | + wrapper.apply("id="+id); | ||
| 59 | + return employeeMapper.selectList(wrapper); | ||
| 60 | + } | ||
| 61 | + | ||
| 62 | + /** | ||
| 63 | + * http://localhost:8081/mybatis_plus/mpVuln03?id=1%20or%201=1 | ||
| 64 | + * @param id | ||
| 65 | + * @return | ||
| 66 | + * last 关键字导致的 SQL 注入 | ||
| 67 | + */ | ||
| 68 | + | ||
| 69 | + @RequestMapping("/mybatis_plus/mpVuln03") | ||
| 70 | + public List<Employee> mpVuln03( String id) { | ||
| 71 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 72 | + wrapper.last("order by " + id); | ||
| 73 | + return employeeMapper.selectList(wrapper); | ||
| 74 | + } | ||
| 75 | + | ||
| 76 | + /** | ||
| 77 | + * http://localhost:8081/mybatis_plus/mpVuln04?id=1%20or%201=1 | ||
| 78 | + * @param id | ||
| 79 | + * @return | ||
| 80 | + * exists 关键字导致的 SQL 注入 | ||
| 81 | + */ | ||
| 82 | + | ||
| 83 | + @RequestMapping("/mybatis_plus/mpVuln04") | ||
| 84 | + public List<Employee> mpVuln04( String id) { | ||
| 85 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 86 | + wrapper.exists("select * from employees where id = " + id); | ||
| 87 | + return employeeMapper.selectList(wrapper); | ||
| 88 | + } | ||
| 89 | + | ||
| 90 | + /** | ||
| 91 | + * http://localhost:8081/mybatis_plus/mpVuln05?id=1%20or%201=1 | ||
| 92 | + * @param id | ||
| 93 | + * @return | ||
| 94 | + * notExists 关键字导致的 SQL 注入 | ||
| 95 | + */ | ||
| 96 | + | ||
| 97 | + @RequestMapping("/mybatis_plus/mpVuln05") | ||
| 98 | + public List<Employee> mpVuln05( String id) { | ||
| 99 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 100 | + wrapper.notExists("select * from employees where id = " + id); | ||
| 101 | + return employeeMapper.selectList(wrapper); | ||
| 102 | + } | ||
| 103 | + | ||
| 104 | + /** | ||
| 105 | + * http://localhost:8081/mybatis_plus/mpVuln06?id=1%20or%201=1 | ||
| 106 | + * @param id | ||
| 107 | + * @return | ||
| 108 | + * having 关键字的 SQL 注入 | ||
| 109 | + */ | ||
| 110 | + | ||
| 111 | + @RequestMapping("/mybatis_plus/mpVuln06") | ||
| 112 | + public List<Employee> mpVuln06( String id) { | ||
| 113 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 114 | + wrapper.notExists("select * from employees where id = " + id); | ||
| 115 | + return employeeMapper.selectList(wrapper); | ||
| 116 | + } | ||
| 117 | + | ||
| 118 | + /** | ||
| 119 | + * http://localhost:8081/mybatis_plus/orderby01?id=1%20or%201=1 | ||
| 120 | + * @param id | ||
| 121 | + * @return | ||
| 122 | + */ | ||
| 123 | + | ||
| 124 | + @RequestMapping("/mybatis_plus/orderby01") | ||
| 125 | + public List<Employee> orderby01( String id) { | ||
| 126 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 127 | + wrapper.notExists("select * from employees where id = " + id); | ||
| 128 | + return employeeMapper.selectList(wrapper); | ||
| 129 | + } | ||
| 130 | + | ||
| 131 | + /** | ||
| 132 | + * http://localhost:8081/mybatis_plus/orderby02?id=1%20or%201=1 | ||
| 133 | + * @param id | ||
| 134 | + * @return | ||
| 135 | + */ | ||
| 136 | + | ||
| 137 | + @RequestMapping("/mybatis_plus/orderby02") | ||
| 138 | + public List<Employee> orderby02( String id) { | ||
| 139 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 140 | + wrapper.notExists("select * from employees where id = " + id); | ||
| 141 | + return employeeMapper.selectList(wrapper); | ||
| 142 | + } | ||
| 143 | + | ||
| 144 | + /** | ||
| 145 | + * http://localhost:8081/mybatis_plus/orderby03?id=1%20or%201=1 | ||
| 146 | + * @param id | ||
| 147 | + * @return | ||
| 148 | + */ | ||
| 149 | + | ||
| 150 | + @RequestMapping("/mybatis_plus/orderby03") | ||
| 151 | + public List<Employee> orderby03( String id) { | ||
| 152 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 153 | + wrapper.notExists("select * from employees where id = " + id); | ||
| 154 | + return employeeMapper.selectList(wrapper); | ||
| 155 | + } | ||
| 156 | + | ||
| 157 | + /** | ||
| 158 | + * http://localhost:8081/mybatis_plus/mpSec02?id=1%20or%201=1 | ||
| 159 | + * @param id | ||
| 160 | + * @return | ||
| 161 | + */ | ||
| 162 | + | ||
| 163 | + @RequestMapping("/mybatis_plus/mpSec02") | ||
| 164 | + public List<Employee> mpSec02( String id) { | ||
| 165 | + QueryWrapper<Employee> wrapper = new QueryWrapper<>(); | ||
| 166 | + wrapper.apply("id={0}",id); | ||
| 167 | + return employeeMapper.selectList(wrapper); | ||
| 168 | + } | ||
| 169 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -11,6 +11,4 @@ | |||
| 11 | 11 | ||
| 12 | 12 | @Repository | |
| 13 | 13 | public interface EmployeeMapper extends BaseMapper<Employee> { | |
| 14 | - | ||
| 15 | - List<Employee> selectByName(@Param("name") String name); | ||
| 16 | 14 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,35 @@ | |||
| 1 | + package com.drunkbaby.pojo; | ||
| 2 | + | ||
| 3 | + import com.baomidou.mybatisplus.annotation.TableName; | ||
| 4 | + | ||
| 5 | + @TableName("employees") | ||
| 6 | + public class Employee { | ||
| 7 | + | ||
| 8 | + private Integer id; | ||
| 9 | + private String name; | ||
| 10 | + private String work; | ||
| 11 | + | ||
| 12 | + public Integer getId() { | ||
| 13 | + return id; | ||
| 14 | + } | ||
| 15 | + | ||
| 16 | + public void setId(Integer id) { | ||
| 17 | + this.id = id; | ||
| 18 | + } | ||
| 19 | + | ||
| 20 | + public String getName() { | ||
| 21 | + return name; | ||
| 22 | + } | ||
| 23 | + | ||
| 24 | + public void setName(String name) { | ||
| 25 | + this.name = name; | ||
| 26 | + } | ||
| 27 | + | ||
| 28 | + public String getWork() { | ||
| 29 | + return work; | ||
| 30 | + } | ||
| 31 | + | ||
| 32 | + public void setWork(String work) { | ||
| 33 | + this.work = work; | ||
| 34 | + } | ||
| 35 | + } | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,12 @@ | |||
| 1 | + <?xml version="1.0" encoding="UTF-8"?> | ||
| 2 | + <!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN" "http://mybatis.org/dtd/mybatis-3-mapper.dtd"> | ||
| 3 | + | ||
| 4 | + <mapper namespace="org.joychou.mapper.UserMapper"> | ||
| 5 | + | ||
| 6 | + <resultMap type="com.drunkbaby.pojo.Employee" id="Employee"> | ||
| 7 | + <id column="id" property="id" javaType="java.lang.Integer" jdbcType="NUMERIC"/> | ||
| 8 | + <id column="name" property="username" javaType="java.lang.String" jdbcType="VARCHAR"/> | ||
| 9 | + <id column="work" property="password" javaType="java.lang.String" jdbcType="VARCHAR"/> | ||
| 10 | + </resultMap> | ||
| 11 | + | ||
| 12 | + </mapper> | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,8 @@ | |||
| 1 | + CREATE TABLE IF NOT EXISTS `mp_test`( | ||
| 2 | + `id` INT UNSIGNED AUTO_INCREMENT, | ||
| 3 | + `name` VARCHAR(255) NOT NULL, | ||
| 4 | + `work` VARCHAR(255) NOT NULL, | ||
| 5 | + PRIMARY KEY (`id`) | ||
| 6 | + )ENGINE=InnoDB DEFAULT CHARSET=utf8; | ||
| 7 | + INSERT INTO `employees` VALUES (1, 'drunkbaby', 'eat'); | ||
| 8 | + INSERT INTO `employees` VALUES (2, 'dll', 'love'); | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -2,6 +2,10 @@ | |||
| 2 | 2 | <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | |
| 3 | 3 | xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd"> | |
| 4 | 4 | <modelVersion>4.0.0</modelVersion> | |
| 5 | + <packaging>pom</packaging> | ||
| 6 | + <modules> | ||
| 7 | + <module>MybatisPluSqli</module> | ||
| 8 | + </modules> | ||
| 5 | 9 | <parent> | |
| 6 | 10 | <groupId>org.springframework.boot</groupId> | |
| 7 | 11 | <artifactId>spring-boot-starter-parent</artifactId> | |
@@ -43,13 +47,26 @@ | |||
| 43 | 47 | <artifactId>mybatis-plus-boot-starter</artifactId> | |
| 44 | 48 | <version>3.4.0</version> | |
| 45 | 49 | </dependency> | |
| 50 | + | ||
| 46 | 51 | <!--mybatisplusextension, mybatispluscore--> | |
| 47 | 52 | <dependency> | |
| 48 | 53 | <groupId>com.baomidou</groupId> | |
| 49 | 54 | <artifactId>mybatis-plus-extension</artifactId> | |
| 50 | 55 | <version>3.4.0</version> | |
| 51 | 56 | </dependency> | |
| 52 | 57 | ||
| 58 | + <dependency> | ||
| 59 | + <groupId>org.apache.logging.log4j</groupId> | ||
| 60 | + <artifactId>log4j-core</artifactId> | ||
| 61 | + <version>2.9.1</version> | ||
| 62 | + </dependency> | ||
| 63 | + | ||
| 64 | + <dependency> | ||
| 65 | + <groupId>org.apache.logging.log4j</groupId> | ||
| 66 | + <artifactId>log4j-api</artifactId> | ||
| 67 | + <version>2.9.1</version> | ||
| 68 | + </dependency> | ||
| 69 | + | ||
| 53 | 70 | </dependencies> | |
| 54 | 71 | ||
| 55 | 72 | <build> | |
| Back | FazBrowse Home | New Git URL |
0 commit comments