You are on page 1of 10

SURABAYA HACKER LINK

SQL Injection (Bypass Login)


*education purpose only
Apa itu SQL injection ?
 SQL injection is a code injection technique, used to
attack data-driven applications, in which malicious SQL
statements are inserted into an entry field for
execution (e.g. to dump the database contents to the
attacker).
Source: wikipedia
 SQL injection adalah teknik injeksi yang bertujuan
menyerang database, dimana statement SQL berbahaya
dimasukan/disuntikan kedalam eksekusi statement SQL

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Apa itu SQL injection ?

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Jenis – Jenis SQLi ?
 BEUSTQ
 Boolean
 Error
 Union
 Stacked
 Query
 Time

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Dimana kita melakukan SQLi?
 POST DATA
 GET DATA
 USER-AGENT
 dsb

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Kenapa melakukan SQLi?
 Dumping data
 Bypass Login

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Lalu Bagaimana Caranya?
 POC (Piye Om Carane)

https://s.id/2Tb8F

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Lalu bagaimana agar aman dari
SQLi?
 Use a famous CMS or static-site
 Use Prepared Statement|
e.g:https://www.w3schools.com/php/php_mysql_prepared_statements.asp

 Use htaccess to manipulate url

www.surabayahackerlink.org fb.com/surabayahackerlink.org
Terima Kasih sudah datang dan mendengarkan
and let the sky dark forever

Created by ./laztname www.surabayahackerlink.org fb.com/surabayahackerlink.org


It’s not yet over

Time to Practice
Practice Make Perfect? NO!
Perfect Practice Make Perfect !

Created by ./laztname www.surabayahackerlink.org fb.com/surabayahackerlink.org

You might also like