SQL
Injection
Sql
injecttion is an action of hacking is done in the client application
by modifying the SQL command that is in memory clien application and
also a technique to exploit a web application that uses database for
storing therein data.
Cause
of sql Injection
Absence
of teh handling of character pick one (‘) and double minus (--)
which causes the application can be compromised with sql sintax.so
the attacker insert sql sintax into parameter or form.
Danger
of SQL Injection
- This technique allows someone enter to system without having to have account.
- Enable someone edit,delete, and insert data to database.
- SQl injection can do only with browser.
 
Tidak ada komentar:
Posting Komentar