Perform a sql injection attack in the search for users box

Assignment Help Database Management System
Reference no: EM132135940

SQL injection on a search

The way Search performs its task is by executing the following query (in a php script):

         $var=stripslashes($_POST['search']);
         $query = "SELECT username from lab1_login where username ='".$var."'";

The structure of the database table that is maintained by the webservice and on which this query runs is as follows:

mysql> desc lab1_login;

Field

Type

Null

Key

Default

Extra

uid            

int(11)  

NO

PRI


auto_increment

username

varchar(255)

YES




password

varchar(255)

YES




Your task is to now perform a SQL Injection attack in the "Search for users" box such that it prints out all the usernames and passwords.

Reference no: EM132135940

Questions Cloud

What can you do to identify duplicated data : What can you do to identify duplicated when the patient is being registered and after?
What is the probability that the student answers : If the student randomly guesses on each questions, what is the probability that the student answers fewer than 4 questions correctly?
Produce a report with descriptive report and column headings : Produce a report with descriptive report and column headings. Be sure there is enough data to prove the selection and sort worked as required.
What is the probability that the student answers : If the student randomly guesses on each question , what is the probability that the student answers 3 questions correctly?
Perform a sql injection attack in the search for users box : Your task is to now perform a SQL Injection attack in the "Search for users" box such that it prints out all the usernames and passwords.
What is the set of possible values of variable x : A coin is flipped five times in an experiment. If x is the number of heads that turn out in the experiment, what is the set of possible values of variable x?
What is the df value for the t statistic for study : An independent-measures study has one sample with n = 10 and a second sample with n = 15 to compare two experimental treatments
Dogs weight and how long the dog lived : The following is data a veterinarian collected from some of her clients. it is a rough estimate % of dogs weight and how long the dog lived
Write a pl-sql stored function that takes username : Write a PL/SQL stored function that takes username as input and returns number of documents that user has permissions to view.

Reviews

Write a Review

Database Management System Questions & Answers

  Advantages and disadvantages of a database system

Describe the major advantages and disadvantages of a database system approach to managing data

  Write the sql code to change the job code

Write the SQL code to change the job code to 501 for the person whose personnel number is 106. After you have completed the task, examine the results, and then reset the job code to its original value.

  Database triggers are utilized to record logins by users

Several times, database triggers are utilized to record logins by users. Here is the example of login trigger that inserts row into table every time a user connects.

  Design the logical structure of a database

Relational Database Systems - COMP 1005 Design the logical structure of a database using Entity-Relationship diagram and Apply normalization techniques to reduce redundancy in a database.

  How virtual applications and desktops or both will delivered

Regional Gardens Ltd is a company that runs number related gardening enterprises. It has a large display garden that it opens for public inspection a number of times in a year.

  Create a data table to show how market share affect profit

Create a two-way data table to show how market share and unit price affect total profit. Let you market share change from 20% to 50% with an increment of 1%.

  Evaluate requirements and select appropriate parameters

Advanced Database Administration (COMP 0343) Manage client-server connections using RDBMS Net Services - Evaluate requirements and select appropriate parameters to ensure effective storage management in a database system.

  Explain the terms rollback and commit

What is the system catalog or data dictionary? Why do you care? What are the user_*, all_* and dba_* views?

  Identify the data analytics tasks

Provide a clear statement of the aims and objectives of the data analytics study and the possible outcomes in terms of discovered knowledge and its potential application towards solution of the problem. In this section you need to discuss the busi..

  Explain the importance of internal tools that are available

Explain the importance of internal tools that are available within a DBMS. Please provide an example of one of these tools.

  Eamples of open-source and proprietary databases

Write a 4-5 page paper in which you distinguish between open-source and proprietary databases. Address the following in your paper: Examples of open-source and proprietary databases

  Assignment of database design

Create a data dictionary that includes the following: a. A description of the content for each field b. The data type of each field ac. The format the data will be stored as in the field d. The range of value for the field e. A label, as required, i..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd