dstergiou

dstergiou

Hello,

first of all i apologize if this is a very basic question, but i only started playing with Elixir last week, and my knowledge of Elixir and Phoenix is minimal.

I am creating a webapp based on Elixir / Phoenix that is on purpose vulnerable to several web attacks. What i am trying to achieve now is a basic SQL Injection, but it seems that Phoenix is using parameterized queries which makes it impossible to have an SQL injection.

The code so far looks like this:

content = Ecto.Adapters.SQL.query!(
          MyApp.Repo, "SELECT name,data from contents WHERE name=$1", [params["name"]]
       )

If i execute the code with a typical SQL injection string like ' OR '1' = ‘1then Phoenix replies with:

SELECT name,data from contents WHERE name=$1 [“’ OR ‘1’ = ‘1”]

If i execute the code with some valid name, then i see this:

SELECT name,data from contents WHERE name=$1 [“Per”]
[[“Per”, “This is a test”]]

Which is what i would expect from this query.
So, my question is, is there a way to write the query code to make this SQL injection viable?

In Python, it was as simple as:

if request.method == 'POST':
        input = request.POST.get('input')
        query = "SELECT * from levels_content WHERE name = '%s'" % input
        result = Content.objects.raw(query)

Again apologies if this is a very basic question, and thanks in advance for the help

Showing Posts 4 to 1

dstergiou

dstergiou OP

Thanks, that did the trick, here is the final line:

    name = params["name"]
    content = Ecto.Adapters.SQL.query!(
      ElixirTrustlyctf.Repo, "SELECT name,data from contents WHERE name=\'#{name}\'", []
    )

Cheers

hauleth

hauleth

You can do the same using Ecto itself:

MyApp.Repo.query("SELECT id FROM posts WHERE title like #{input}", [])
dstergiou

dstergiou OP

Hey,

i checked here: Postgrex — Postgrex v0.22.2 for query/4 and it seems that passing attributes as parameters is mandatory - at least this is what i understand from this example:

Postgrex.query(conn, "SELECT id FROM posts WHERE title like $1", ["%my%"])

Ideally i would like to do some string interpolation, and end up with something like:
Postgrex.query(conn, "SELECT id FROM posts WHERE title like #{input}")

input being what i received from the HTML form

darkmarmot

darkmarmot

You probably want to drop down to a lower level library like :postgrex so that you can create injectable queries by hand?

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews