Skip to main content

SQL Injection, Teknik Hacking Klasik Namun Sakti Mantraguna

SQL injection, sebuah metode hacking sederhana namun memiliki efek yang sungguh luar biasa. Hanya dengan memasukkan query-query sederhana, Sang hacker dapat mengambil alih kendali website. Mulai dari memasukkan data, merubah data, menghapus isi website, sampai mematikan (deface) website tersebut.

Pertama, mungkin saya jelaskan terlebih dahulu apa itu SQL. SQL (Structured Query Language) merupakan bahasa pemrograman database yang banyak digunakan oleh aplikasi website pada saat ini. Banyak aplikasi database yang mengunakan SQL sebagai bahasa pengeloaan data yang disimpan dalam database, diantaranya adalah Oracle, Mic. Access, SQL Server, dan yang paling terkenal adalah MySQL.

SQL injection, mulai menjadi sebuah metode fenomenal pada tahun 2004. Metode ini memanfaatkan rapuhnya script aplikasi website yang dibangun oleh programmer. Tentu Anda masih ingat dengan kasus bobolnya website KPU saat Pemilu 2004 kemarin. Sang Hacker hanya dengan menggunakan SQL Injection mampu mengobok-obok situs yang berisikan jumlah suara pemilu.

SQL Injection dapat dilakukan dengan berbagai cara, diantara adalah melalui form yang tersedia pada website dan melalui URL website itu sendiri. Khusus untuk Anda sebagai programmer website pemula, yang perlu Anda perhatikan adalah untuk tidak memproses sebuah input atau perintah dari pengguna website sebelum melewati tahap pemeriksaan isi dari input tersebut. Karakter dari isi perintah/input yang harus difilter adalah tanda petik ganda ( " ), tanda petik tunggal ( ' ), titik koma ( ; ), sama dengan ( = ).

Apabila Anda programmer PHP, Anda dapat menggunakan fungsi str_replace. Sedangkan bila Anda programmer ASP, Anda dapat menggunakan fungsi Replace.

Mungkin saat ini metode tersebut sudah agak basi dikalangan Hacker, namun bukan berarti Anda tidak waspada bukan? Jadi tidak heran bila Anda sebagai pemilik website harus tetap ekstra waspada terhadap potensi bahaya dari metode ini.

Popular posts from this blog

Thank You, it's important or not?

Thank You, it's important we say after other people help us? Absolutely yes. Why? The expresion of thank you is a expresion to other people who give their time to do something for us. We can say thank you to parents, teacher, trader, police man, until parking man. It's has become a traditon of eastern people like to politeness. Always to say thank you for more polite, especially to old people. But the expresion of thank you for some people like medicine which can make our feel fresh. Why? Because has been become a basic characteristic oh human like to appreciated by other people. When other people appreciate your job? What's your feel? Happy, isn't right? The expresion of thank you can become medicine of our heart. Ya.. because we could avoided from arrogant, conceited, until jealous. If we say thank you, its same to thanks be to god. So, it'snot wrong time to start usually say thank you to other people. With appreciate other people, we can make happy other people,...

"Tugu Jogja", The famous Landmark of Yogyakarta

Tugu Jogja, is one of famous tour place and historic monument in Yogyakarta, Indonesia. The monument is stand on meeting point of Pangeran Mangkubumi Street, Jendral Sudirman Street, A.M Sangaji Street, and Diponegoro Street, Yogyakarta City. The monument has built one year after Keraton Yogyakarta (The palace of Yogyakarta) was builded. The monument describe Manunggaling Kawula Gusti (The technical term of Javanese language) or the unity spirit of citizenry and the authorities to fight colonial. The unity spirit was described in the monument, the shape of monument's pole is cylinder or gilig (The technical term of Javanese language) and the shape of the top is circle or golong (The technical term of Javanese language), so the monument is called " Tugu Golong-Gilig ". The height the monument is about 25 meters. But the monument was fall out caused by earthquake in 10 Juni 1867. In 1889, Netherland's goverment renovated the monument. The monument has made with shape...

Avoid Google Adsense Public Sevice Advertise (PSAs) at Blogger

Might be some blogger have same problem with me, how to avoid Google Adsense Public Sevice Advertise (PSAs). Although they have used supported language, but the PSAs still appear. How to avoid that? The answer is, you can use "Section Targeting". Section targeting allows you to suggest sections of your text and HTML content that you'd like Google to emphasize or downplay when matching ads to your site's content. To implement section targeting, you'll need to add a set of special HTML comment tags to your code. These tags will mark the beginning and end of whichever section(s) you'd like to emphasize or de-emphasize for ad targeting. The HTML tags to emphasize a page section take the following format: <!-- google_ad_section_start --> your content here (supported language).. your content here (supported language).. your content here (supported language).. <!-- google_ad_section_end --> You can use section targeting to make suggestions about as many s...