dstergiou
Hello,
first of all i apologize if this is a very basic question, but i only started playing with Elixir last week, and my knowledge of Elixir and Phoenix is minimal.
I am creating a webapp based on Elixir / Phoenix that is on purpose vulnerable to several web attacks. What i am trying to achieve now is a basic SQL Injection, but it seems that Phoenix is using parameterized queries which makes it impossible to have an SQL injection.
The code so far looks like this:
content = Ecto.Adapters.SQL.query!(
MyApp.Repo, "SELECT name,data from contents WHERE name=$1", [params["name"]]
)
If i execute the code with a typical SQL injection string like ' OR '1' = ‘1then Phoenix replies with:
SELECT name,data from contents WHERE name=$1 [“’ OR ‘1’ = ‘1”]
If i execute the code with some valid name, then i see this:
SELECT name,data from contents WHERE name=$1 [“Per”]
[[“Per”, “This is a test”]]
Which is what i would expect from this query.
So, my question is, is there a way to write the query code to make this SQL injection viable?
In Python, it was as simple as:
if request.method == 'POST':
input = request.POST.get('input')
query = "SELECT * from levels_content WHERE name = '%s'" % input
result = Content.objects.raw(query)
Again apologies if this is a very basic question, and thanks in advance for the help
Trending in Questions
Other Trending Topics
Latest Phoenix Threads
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #blog-post
- #ai
- #phoenix_html
- #elixirconf-us
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming










Showing Posts 1 to 4- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
darkmarmot
You probably want to drop down to a lower level library like
:postgrexso that you can create injectable queries by hand?dstergiou
Hey,
i checked here: Postgrex — Postgrex v0.22.2 for
query/4and it seems that passing attributes as parameters is mandatory - at least this is what i understand from this example:Postgrex.query(conn, "SELECT id FROM posts WHERE title like $1", ["%my%"])Ideally i would like to do some string interpolation, and end up with something like:
Postgrex.query(conn, "SELECT id FROM posts WHERE title like #{input}")inputbeing what i received from the HTML formhauleth
You can do the same using Ecto itself:
dstergiou
Thanks, that did the trick, here is the final line:
Cheers