摘要
由于PHP本身的缺陷和应用程序开发者安全防范意识不强,使得应用PHP技术的网站存在很多安全问题,而SQL注入就是利用此类漏洞来实施攻击。论文结合应用开发中的经验剖析攻击者SQL注入的方法和入侵的思路,并且提出相应的防御策略。
Due to the defects of the PHP language itself and weak awareness of network security of application programmers, there exist various security issues which are usually used by SQL injection attackers. Regarding to application programming experiences, some methods of SQL injection attackers were discussed and the intents of attackers behind such threats were looked into. Countermeasures to deal with SQL injection attack were also provided accordingly.
出处
《信息安全与通信保密》
2006年第9期154-157,160,共5页
Information Security and Communications Privacy