sql注入和预防--PreparedStatement

sql注入

package com.wkw.jdbc;

import com.wkw.pojo.Account;
import org.testng.annotations.Test;

import java.sql.*;
import java.util.ArrayList;
import java.util.List;


public class JDBCDemo5 {


    @Test

    public void Login() throws Exception {
        //1.注册驱动
       // Class.forName("com.mysql.jdbc.Driver");
        //2.获取链接

        String url="jdbc:mysql://localhost:3306/test?useUnicode=true&characterEncoding=utf-8&useSSL=false";
        String username = "root";
        String password = "root";
        Connection conn = DriverManager.getConnection(url,username,password);

        //3.接受用户名和密码
        String name = "zhangsan";
        String pwd = "123";
        String sql = "select * from user where username = '"+name+"' and password = '"+pwd+"'";
        //获取stmt对象
        Statement stmt = conn.createStatement();

        //执行sql
        ResultSet rs = stmt.executeQuery(sql);

        //判断是否登陆成功
        if(rs.next()){
            System.out.println("登陆成功");
        }else{
            System.out.println("登陆失败");
        }

        //7,释放资源
       rs.close();
       stmt.close();
       conn.close();
    }

/*---------------------------普通登陆-------------------------------------*/


    @Test
    public void Login_inject() throws Exception {
        //1.注册驱动
        // Class.forName("com.mysql.jdbc.Driver");
        //2.获取链接
        String url="jdbc:mysql://localhost:3306/test?useUnicode=true&characterEncoding=utf-8&useSSL=false";
        String username = "root";
        String password = "root";
        Connection conn = DriverManager.getConnection(url,username,password);
        //3.接受用户名和密码
        String name = "sdfgfsdg";
        String pwd = "' or ' 1 ' = ' 1";//注入,拼字符串

        String sql = "select * from user where username = '"+name+"' and password = '"+pwd+"'";
        //获取stmt对象
        Statement stmt = conn.createStatement();
        //执行sql
        ResultSet rs = stmt.executeQuery(sql);
        //判断是否登陆成功
        if(rs.next()){
            System.out.println("登陆成功");
        }else{
            System.out.println("登陆失败");
        }

        //7,释放资源
        stmt.close();
        conn.close();



    }
}

/*----------------------------sql注入------------------------------------------------------*/

预防SQL注入

package com.wkw.jdbc;

import org.testng.annotations.Test;

import java.sql.*;

/*PreparedStatement*/
public class JDBCDemo6 {


    public static void main(String[] args) throws  Exception {
        //1.注册驱动
        // Class.forName("com.mysql.jdbc.Driver");
        //2.获取链接

        String url = "jdbc:mysql://localhost:3306/test?useUnicode=true&characterEncoding=utf-8&useSSL=false";
        String username = "root";
        String password = "root";
        Connection conn = DriverManager.getConnection(url, username, password);
        //3.接受用户名和密码
        String name = "zhangsan";
        String pwd = "' or ' 1 ' = ' 1";
        //定义sql
        String sql = "select * from user where username = ? and password = ?";
        System.out.println(sql);
        /* 获取pstmt对象 */
        PreparedStatement pstmt = conn.prepareStatement(sql);


        //设置?的值
        pstmt.setString(1, name);
        pstmt.setString(2, pwd);
        System.out.println(sql);
        //执行sql
        ResultSet rs = pstmt.executeQuery();

        //判断是否登陆成功
        if (rs.next()) {
            System.out.println("登陆成功");
        } else {
            System.out.println("登陆失败");

        }



        //7,释放资源
        rs.close();
        pstmt.close();
        conn.close();


    }


}






  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值