dstergiou

dstergiou

Hello,

first of all i apologize if this is a very basic question, but i only started playing with Elixir last week, and my knowledge of Elixir and Phoenix is minimal.

I am creating a webapp based on Elixir / Phoenix that is on purpose vulnerable to several web attacks. What i am trying to achieve now is a basic SQL Injection, but it seems that Phoenix is using parameterized queries which makes it impossible to have an SQL injection.

The code so far looks like this:

content = Ecto.Adapters.SQL.query!(
          MyApp.Repo, "SELECT name,data from contents WHERE name=$1", [params["name"]]
       )

If i execute the code with a typical SQL injection string like ' OR '1' = ‘1then Phoenix replies with:

SELECT name,data from contents WHERE name=$1 [“’ OR ‘1’ = ‘1”]

If i execute the code with some valid name, then i see this:

SELECT name,data from contents WHERE name=$1 [“Per”]
[[“Per”, “This is a test”]]

Which is what i would expect from this query.
So, my question is, is there a way to write the query code to make this SQL injection viable?

In Python, it was as simple as:

if request.method == 'POST':
        input = request.POST.get('input')
        query = "SELECT * from levels_content WHERE name = '%s'" % input
        result = Content.objects.raw(query)

Again apologies if this is a very basic question, and thanks in advance for the help

Marked As Solved

hauleth

hauleth

You can do the same using Ecto itself:

MyApp.Repo.query("SELECT id FROM posts WHERE title like #{input}", [])

Last Post!

dstergiou

dstergiou OP

Thanks, that did the trick, here is the final line:

    name = params["name"]
    content = Ecto.Adapters.SQL.query!(
      ElixirTrustlyctf.Repo, "SELECT name,data from contents WHERE name=\'#{name}\'", []
    )

Cheers

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
ryanwinchester
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted” Version...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews