Injeksi SQL (SqlInjection) adalah sebuah teknik yang menyalahgunakan sebuah celah keamanan yang terjadi dalam lapisan basis data sebuah aplikasi.
Pengertian SQL Injection
SQL Injection merupakan sebuah teknik hacking dimana seorang penyerang dapat memasukkan perintah-perintah SQL melalui url untuk dieksekusi oleh database. Penyebab utama dari celah ini adalah variable yang kurang di filter :
id=$id;……. > Got Error
Hal pertama yang harus kita lakukan adalah mengetahui apakah situs tersebut terkena celah SQL Injection atau tidak, yaitu dengan membuat sebuah error dengan menambahkan karakter ‘ setelah atau sesudah angka pada url.
Pertama kita cari dulu website yang memiliki celah SQL Injection. silahkan sobat cari target di google dengan menggunakan dork.
view_items.php? id =
home.php? cat =
item_book.php? CAT =
www / index.php? page =
schule / termine.php? view =
goods_detail.php? data =
storemanager / content / item.php? page_code =
view_items.php? id =
customer / board.htm? mode =
index.php? section =
index.php? page =
id / publications.php? id =
events / detail.php? ID =
forum / profile.php? id =
media / pr.php? id =
content.php? ID =
news.php? id =
content / index.php? id =
index.php? modus =
modules.php? bookid =
katalog / main.php? cat_id =
index.php? page =
detail.php? prodid =
produk / product.php? pid =
news.php? id =
detail.php? id =
category.php? id =
hm / inside.php? id =
index.php? area_id =
gallery.php? id =
products.php? cat =
products.php? cat =
general.php? id =
news.php? t =
usb / devices / showdev.php? id =
content / detail.php? id =
templet.php? acticle_id =
news / news / title_show.php? id =
product.php? id =
index.php? url =
news.php? id =
id / news / fullnews.php? newsid =
deal_coupon.php? cat_id =
show.php? id =
blog / index.php? idBlog =
content.php? id =
viewapp.php? id =
item.php? id =
profil / profile.php? profileid =
event.php? id =
gallery.php? id =
category.php? CID =
corporate / newsreleases_more.php? id =
print.php? id =
view_items.php? id =
more_details.php? id =
county-fakta / buku harian / vcsgen.php? id =
idlechat / message.php? id =
podcast / item.php? pid =
products.php? act =
details.php? prodId =
socsci / events / full_details.php? id =
ourblog.php? categoryid =
mall / more.php? ProdID =
arsip / get.php? message_id =
review / review_form.php? item_id =
index.php? pid =
download.php? id =
shop / category.php? cat_id =
i-know / content.php? page =
store / index.php? cat_id =
yacht_search / yacht_view.php? pid =
pharmaxim / category.php? cid =
print.php? sid =
specials.php? osCsid =
store.php? cat_id =
category.php? cid =
displayrange.php? rangeid =
product.php? id =
csc / news-details.php? cat =
products-display-details.php? prodid =
stockists_list.php? area_id =
news / newsitem.php? newsID =
index.php? pid =
newsitem.php? newsid =
category.php? id =
news / newsitem.php? newsID =
details.php? prodId =
publikasi / publikasi.php? id =
category.php? cid =
product / detail.php? id =
news / newsitem.php? newsID =
details.php? prodID =
item.php? item_id =
edition.php? area_id =
page.php? area_id =
view_newsletter.php? id =
feedback.php? title =
freedownload.php? bookid =
fullDisplay.php? item =
getbook.php? bookid =
GetItems.php? Itemid =
view.php? cid =
view_cart.php? title =
view_detail.php? ID =
viewcart.php? CartId =
viewCart.php? userID =
viewCat_h.php? idCategory =
viewevent.php? EventID =
viewitem.php? recor =
viewPrd.php? idcategory =
ViewProduct.php? Misc =
voteList.php? item_ID =
whatsnew.php? idCategory =
WsAncillary.php? ID =
WsPages.php? ID = noticiasDetalle.php? Xid =
sitio / item.php? idcd =
index.php? site =
de / content.php? page_id =
gallerysort.php? iid =
products.php? type =
event.php? id =
showfeature.php? id =
home.php? ID =
tas / event.php? id =
profile.php? id =
details.php? id =
past-event.php? id =
index.php? action =
site / products.php? prodid =
page.php? pId =
resources / vulnerabilities_list.php? id =
site.php? id =
products / index.php? rangeid =
global_projects.php? cid =
publikasi / view.php? id =
display_page.php? id =
pages.php? ID =
lmsrecords_cd.php? cdid =
product.php? prd =
cat /? catid =
produk / produk-list.php? id =
debat-detail.php? id =
cbmer / congres / page.php? LAN =
content.php? id =
news.php? ID =
photogallery.php? id =
index.php? id =
product / product.php? product_no =
nyheder.htm? show =
book.php? ID =
print.php? id =
detail.php? id =
book.php? id =
content.php? PID =
more_detail.php? id =
content.php? id =
view_items.php? id =
view_author.php? id =
main.php? id =
bahasa inggris / fonction / print.php? id =
magazines / adult_magazine_single_page.php? magid =
product_details.php? prodid =
magazines / adult_magazine_full_year.php? magid =
products / card.php? prodID =
catalog / product.php? cat_id =
e_board / memodifikasiform.html? code =
community / calendar-event-fr.php? id =
products.php? p =
news.php? id =
lihat /
7/9628 / 1.html? reply =
product_details.php? prodid =
catalog / product.php? pid =
rating.php? id =
? halaman =
katalog / main.php? cat_id =
index.php? page =
detail.php? prodid =
produk / product.php? pid =
news.php? id =
book_detail.php? BookID =
katalog / main.php? cat_id =
katalog / main.php? cat_id =
default.php? cPath =
katalog / main.php? cat_id =
katalog / main.php? cat_id =
category.php? catid =
category.php? cat =
category.php? cat =
detail.php? prodID =
detail.php? id =
category.php? id =
hm / inside.php? id =
index.php? area_id =
gallery.php? id =
products.php? cat =
products.php? cat =
media / pr.php? id =
books / book.php? proj_nr =
products / card.php? prodID =
general.php? id =
news.php? t =
usb / devices / showdev.php? id =
content / detail.php? id =
templet.php? acticle_id =
news / news / title_show.php? id =
product.php? id =
index.php? url =
cryolab / content.php? cid =
ls.php? id =
s.php? w =
di luar negeri / page.php? cid =
bayer / dtnews.php? id =
news / temp.php? id =
index.php? url =
book / bookcover.php? bookid =
index.php / en / komponen / pvm /? view =
product / list.php? pid =
cats.php? cat =
software_categories.php? cat_id =
print.php? sid =
docDetail.aspx? chnum =
index.php? section =
index.php? page =
index.php? page =
id / publications.php? id =
events / detail.php? ID =
category.php? c =
main.php? id =
article.php? id =
showproduct.php? productId =
view_item.php? item =
skunkworks / content.php? id =
index.php? id =
item_show.php? id =
publications.php? Id =
index.php? t =
view_items.php? id =
More_Details.php? Id =
Selanjutnya kita akan mencari angka tabel yang bisa kita gunakan untuk perintah2 injection pada tahap selanjutnya. Gunakan perintah union select diikuti jumlah tabel dan tanda - sebelum angka dan diakhiri dengan tanda --. contoh:
kita bisa lihat versi database yang dipake adalah v.5.5.14, jadi pada versi 5 itu berberda dengan versi 4. prosesnya lebih repot pada versi 4, karena untuk melakukan perintah2 SQLi pada versi 4 kita harus menebak 1 per 1 tabel yang ada pada databasenya.