1. Halo Guest, pastikan Anda selalu menaati peraturan forum sebelum mengirimkan post atau thread baru.

Minta tolong, Anti SQL Injection Script in PHP

Discussion in 'Pemrograman Web' started by r4tn4, Jan 23, 2007.

  1. r4tn4

    r4tn4 Super Hero

    Joined:
    Mar 31, 2006
    Messages:
    3,828
    Likes Received:
    2,668
    Location:
    https://www.tikie.online
    Help me plz, buat para coder php,
    script untuk memfilter sql injection,.... sekalian kasih tahu cara make nya,.. udah coba searching tapi binun cara make-nya gimana,....??


    Thanks
     
  2. kaitokid1412

    kaitokid1412 Ads.id Pro

    Joined:
    Sep 5, 2006
    Messages:
    475
    Likes Received:
    0
    1. waktu kamu koding jangan langsung kyak gini:
    select user, pass from table_user when user=namauser and pass=password
    tapi ganti dengan menyeleksi username dulu, baru jika ada, cocokin passnya.
    2. md5 passwordmu
    3. batasi password n username hanya dengan huruf dan angka.
    4. filter inputan, kalo ga salah dengan addslashes (gw lupa)
    5 ada yang mo nambahin?
     
  3. Dengan pembatasan huruf dan angka kayaknya udah bisa. Bisa pake regexp ato bisa juga pake pengalihan ke ascii dengan looping
     
  4. jowo

    jowo Ads.id Fan

    Joined:
    Dec 21, 2006
    Messages:
    118
    Likes Received:
    3
    gunanya buat apa sih filter injection? aku kok gak mudeng
     
  5. handry

    handry Super Hero

    Joined:
    Jan 2, 2006
    Messages:
    760
    Likes Received:
    3
  6. vara

    vara Ads.id Fan

    Joined:
    Jul 20, 2006
    Messages:
    240
    Likes Received:
    0
    Location:
    Mbatam Ailend
    kwi lo mas jowo..
    tentang security website.Biar site php kita biar nggak bisa di hacking orang dengan metode "iject script".Denger² kan katanya "SQL Injection" ini Pernah populer di dunia perhackingan.ga tau persisnya
    cuma denger isu² aja.

    Nah,Ibu Ratna ini keliatanya waspada banget dengan yang satu ini.Emang harus waspadalah.....waspadalah..!
    nyambung ga seh... ;D
     
  7. domainischeap

    domainischeap Ads.id Pro

    Joined:
    Mar 5, 2006
    Messages:
    309
    Likes Received:
    1
    Kayaknya dulu aku pake addslashes() ma mysql_escape_string() gitu gitu dech ....lupa lagih ... :D

    cek di situs sitepoint coba
     
  8. masery

    masery Super Hero

    Joined:
    Aug 3, 2006
    Messages:
    1,567
    Likes Received:
    3
    enkripsi password juga bisa kalo masalah sekuriti, googling yang php code juga banyak sekarang. Beli lisensi ssl aman banget kayak google ama yahoo. ;D ;D ;D
     
  9. handry

    handry Super Hero

    Joined:
    Jan 2, 2006
    Messages:
    760
    Likes Received:
    3
    Lisensi SSL juga harus beli dedicated IP biar makin mantep.
     
  10. biruhijau

    biruhijau Ads.id Fan

    Joined:
    Sep 2, 2006
    Messages:
    180
    Likes Received:
    1
    wah makasih nih infonya.....
     
  11. the9squad

    the9squad Ads.id Starter

    Joined:
    Mar 13, 2007
    Messages:
    96
    Likes Received:
    0
    cara plg mudah utk blocking SQL injection ada dua,

    • jgn pake register globals, tapi pake super globals.
    • Filter input url pake .htaccess <-- easiest
    • Pake MD5 / SHA1 Encryption
     
  12. Radian

    Radian Super Hero

    Joined:
    Aug 11, 2006
    Messages:
    1,780
    Likes Received:
    7
    Gimana contohnya... ::)

    Kasih contoh ya... :D (ktnya easiest)
     
  13. the9squad

    the9squad Ads.id Starter

    Joined:
    Mar 13, 2007
    Messages:
    96
    Likes Received:
    0
    besok pagi yah, dah ngantuk ney
    tapi besok kalo bisa tak kasi contohnya.

    tapi dasarnya pake mod-rewrite yang difilter inputnya kok
    bingung ?

    tunggu besok dey :D :D
     
  14. Radian

    Radian Super Hero

    Joined:
    Aug 11, 2006
    Messages:
    1,780
    Likes Received:
    7
    Oke deh... :)

    Salut... ini baru new comer yg bener2 expert! 8)
     
  15. r4tn4

    r4tn4 Super Hero

    Joined:
    Mar 31, 2006
    Messages:
    3,828
    Likes Received:
    2,668
    Location:
    https://www.tikie.online
    belum ada balesan lagi neh,.....
     

Share This Page