推荐学习书目
› Learn Python the Hard Way
Python Sites
› PyPI - Python Package Index
› http://diveintopython.org/toc/index.html
› Pocoo
值得关注的项目
› PyPy
› Celery
› Jinja2
› Read the Docs
› gevent
› pyenv
› virtualenv
› Stackless Python
› Beautiful Soup
› 结巴中文分词
› Green Unicorn
› Sentry
› Shovel
› Pyflakes
› pytest
Python 编程
› pep8 Checker
Styles
› PEP 8
› Google Python Style Guide
› Code Style from The Hitchhiker's Guide
loading
V2EX  ›  Python

用flask或django还需要防sql注入吗

  •  
  •   loading · Sep 21, 2012 · 12352 views
    This topic created in 5120 days ago, the information mentioned may be changed or developed.
    记得flask文档说我们可以专注于开发,安全问题不怎么需要担心?
    用peewee或者其他orm就不用管这个问题了吧,如果我直接g.db.execu呢
    8 replies  •  1970-01-01 08:00:00 +08:00
    fanzheng
        1
    fanzheng  
       Sep 21, 2012   ❤️ 1
    http://flask.pocoo.org/docs/patterns/sqlite3/#easy-querying

    To pass variable parts to the SQL statement, use a question mark in the statement and pass in the arguments as a list. Never directly add them to the SQL statement with string formatting because this makes it possible to attack the application using SQL Injections.
    Brutal
        2
    Brutal  
       Sep 21, 2012
    我现在在犹豫要不要用ORM。。。
    loading
        3
    loading  
    OP
       Sep 21, 2012
    @fanzheng 下面这样就不会被注入了么?
    user = query_db('select * from users where username = ?',
    [the_username], one=True)

    请问怎么写的才是能被注入的,上面的我看起来像可以被注入的。。。
    例如the_username=";delete * from users"
    fanzheng
        4
    fanzheng  
       Sep 21, 2012
    @loading 我对这个也不怎么熟的。。他说用?用列表不会,

    但是 the_username=";delete * from users" 因为没有参数肯定也不能被注入。
    fanzheng
        5
    fanzheng  
       Sep 21, 2012
    他说不要这样
    user = query_db('select * from users where username = %s' % 请求的参数)

    因为%s 里面可以另外构造一个SQL语句。
    loading
        6
    loading  
    OP
       Sep 21, 2012
    @fanzheng 了然,感谢:-)
    gamexg
        7
    gamexg  
       Sep 22, 2012   ❤️ 2
    user = query_db('select * from users where username = ?',
    [the_username], one=True)

    这里系统会自动对危险字符进行转义。一般将客户端输入的内容作为 query_db 之类函数参数进行提交的都不用担心注入,而自己通过 %s 之类的构建查询字符串就要小心了。
    stackpop
        8
    stackpop  
       Sep 22, 2012
    我用django是自己实现了一个简单的db类
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Privacy   ·   Solana   ·   1041 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 31ms · UTC 18:15 · PVG 02:15 · LAX 11:15 · JFK 14:15
    ♥ Do have faith in what you're doing.