sql注入的问题,PreparedStatement

package cn.itcast.jdbc;

import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;

public class SQLInject {

    public static void main(String[] args) throws SQLException {
        read("lisi");
        System.out.println("-----------------------");
        read("'or 1 or'"); // sql注入,or是sql关键字,1表示真,会查询出全部结果
    }

    static void read(String name) throws SQLException {
        Connection conn = null;
        Statement st = null;
        ResultSet rs = null; 

        try {
            conn = JdbcUtils.getConnection();

            st = conn.createStatement();

            String sql = "select id,name,birthday,money from user where name='"
                    + name + "'";

            rs = st.executeQuery(sql);

            while (rs.next()) {
                System.out.println("id:" + rs.getObject("id") + "\tname:"
                        + rs.getObject("name") + "\tbirthday:"
                        + rs.getObject("birthday") + "\tmoney:"
                        + rs.getObject("money"));
            }

        } finally {
            JdbcUtils.free(rs, st, conn);
        }
    }
}

为解决这个问题可以使用PreparedStatement解决

package cn.itcast.jdbc;

import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;

public class SQLInject {

    public static void main(String[] args) throws SQLException {
        read("lisi");
        System.out.println("-----------------------");
        read("'or 1 or'"); //现在这个查询不到结果
    }

    static void read(String name) throws SQLException {
        Connection conn = null;
        PreparedStatement ps = null;    //预处理的查询语句,过滤掉特殊字符,避免sql注入;PreparedStatement速度比Statement更快一些
        ResultSet rs = null;

        try {
            conn = JdbcUtils.getConnection();

            String sql = "select id,name,birthday,money from user where name=?";
            ps = conn.prepareStatement(sql);
            ps.setString(1, name);      

            rs = ps.executeQuery();

            while (rs.next()) {
                System.out.println("id:" + rs.getObject("id") + "\tname:"
                        + rs.getObject("name") + "\tbirthday:"
                        + rs.getObject("birthday") + "\tmoney:"
                        + rs.getObject("money"));
            }

        } finally {
            JdbcUtils.free(rs, ps, conn);
        }
    }
}

工具类JdbcUtils

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值