<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>SQL Injection&#39; a Giri&#351; ve SQL Injection Nedir&#63; - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 19:49:57 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>furkan</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>furkan</author>
  <pubDate>Per, 22 Tem 2010 11:13:47 +0200</pubDate>
  <description>           video link kirik galiba linki g&amp;#252;ncelleyebilirmisiniz..</description>
</item>
<item>
  <title>voltran</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>voltran</author>
  <pubDate>Pzt, 05 Tem 2010 18:59:23 +0200</pubDate>
  <description>           sanirim sql injection nin kullanildigi yerler a&amp;#231;ik kaynak kodlu hazir yazilim kullanan webcilerin siteleri olsa gerek. &amp;#199;&amp;#252;nk&amp;#252; sql ni kendine g&amp;#246;re olusturan yazilimci &amp;#246;rnegin Members yerine uyeler, User yerine kullanici password yerine sifre olarak tablo acabilir. Bu da tabiki injection yapacak kisiyi baya bir duvara tostlatir diye d&amp;#252;s&amp;#252;n&amp;#252;yorum. Ha simdi diyebilirsinizki bir sekilde ne kullandigini &amp;#246;grendim. E zaten &amp;#246;grendinse ya yazilim dosyamin i&amp;#231;ine girmisindir, Yada sql in i&amp;#231;ine girmisindir. O vakitte Injection a ne gerek var. &lt;br /&gt;Her zaman diyorum ha cebimden para &amp;#231;almisin ha hazir yazilim kullanmissin. Bana hazir yazilimda ekleme yada a&amp;#231;ik kapamaya gelenlerin isini asla almiyorum. ve gelecekte bu isi yapmak bu isten para kazanmak istiyorsaniz sizlerde almayin. &amp;#199;&amp;#252;nk&amp;#252; sizler bu isleri aldik&amp;#231;a ve bu yamalari kapadik&amp;#231;a biz coderlara ihtiyac kalmamakta. Birakin joomlayi, nukeyi istedikleri gibi kullansin kendini uyanik sanan avanaklar. 30 - 40.000 tl teklif verdigim alisveris sitesine adam joomla 5.000 tl veriyor. Bakarmisin hirsiza hem cebimden 30.000 tl &amp;#231;aliyor sonra gelip bende g&amp;#252;venlik a&amp;#231;igi varmi diye soruyo yada ya bu sistem 10.25 tl yaziyo ama m&amp;#252;steri 10,25 tl yazsin istiyo hadi be sen yaparsin veririm sana bi 100 dolar . Hade lennnnn kisaca diyorum</description>
</item>
<item>
  <title>Pely</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Pely</author>
  <pubDate>Sal, 08 Haz 2010 20:47:38 +0200</pubDate>
  <description>           Merhaba arkadaslar  benim bi sorum OLucakta &lt;br /&gt;bilne warsa mail atabilr mi ?&lt;br /&gt;sqL injection da ilK kaydi getirmek icin ne yapabiliRm ?&lt;br /&gt;kullanici adi we sifresini istiyen sayfada&lt;br /&gt;sonuna 'a ekledigimde&lt;br /&gt; war mi yok mu diye koNTrol ettim oK&amp;#233;&lt;br /&gt;select union dan tahmin edemiyorum&lt;br /&gt;ilk kullanici adini we sifresini datadabaseden nasi getirecegim ?&lt;br /&gt;biri mail atabiliRm i*</description>
</item>
<item>
  <title>cihan</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>cihan</author>
  <pubDate>Cmt, 03 Nis 2010 00:57:25 +0200</pubDate>
  <description>           arkadasalr bu site a&amp;#231;iklarini nasil buluyorlar nereye giripde sitenin a&amp;#231;igini bulup bilgilere siziliyor &amp;#246;nlem almak istiyoruz nasil oluyor  a&amp;#231;ik veri tabanina y&amp;#246;nelik bir sey mi</description>
</item>
<item>
  <title>hamza</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>hamza</author>
  <pubDate>Cmt, 13 Mar 2010 01:14:13 +0200</pubDate>
  <description>           SQL ile alakali diger yazilarini okudum, tesekk&amp;#252;r ederim...&lt;br /&gt;Anladigim sey dogru mu  cevap verirseniz sevinirim.&lt;br /&gt;&lt;br /&gt;SQL c&amp;#252;mlesini dinamik olusturuyorsak, (eger alan string) ise tek tirnaklari (') &amp;#231;ift tirnak('') ile degistirdigimizde sql enjeksiyon yapilmasiz imkansiz...&lt;br /&gt;&lt;br /&gt;Eger alanimizin t&amp;#252;r&amp;#252; sayisal bir degerse o zaman gelen bilgidegi rakamt hari&amp;#231; herseyi temizledigimizde sql enjeksiyon yapilmasizi imkansiz oluyor...&lt;br /&gt;&lt;br /&gt;Bu s&amp;#246;yledigim MS SQL i&amp;#231;in ge&amp;#231;erli, MYSQL olsa Tek tirnaklari Slahs Tirnak (\') ile degistirmek gerekli...&lt;br /&gt;&lt;br /&gt;Dogru anlamismiyim? Bu s&amp;#246;ylediklerimi yaptigim takdirde hala sql enejksiyon olabilir mi? olabilirse nasil?&lt;br /&gt;Tesekk&amp;#252;r ederim...&lt;br /&gt;</description>
</item>
<item>
  <title>mehmet</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>mehmet</author>
  <pubDate>Pzt, 08 Mar 2010 11:07:53 +0200</pubDate>
  <description>           aslinda injection i engellemek &amp;#231;ok basit.&lt;br /&gt;&lt;br /&gt;php de &amp;#246;rnek verecek olursak.&lt;br /&gt;&lt;br /&gt;Misal Formdan degerleri &amp;#231;ekerken su ufak kodu kullanalim.&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;$username=strip_tags(mysql_real_escape_string($_POST['username']));&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;yukardaki kodlari formdan her &amp;#231;ektiginizde kullanirsaniz ne injection yer nede html &amp;#231;alisir.&lt;br /&gt;&lt;br /&gt;peki degerler adres &amp;#231;ubugunda ise yani GET fonksiyonuyla degerler &amp;#231;ekiliyorsa ?&lt;br /&gt;&lt;br /&gt;http://ornek.com/haberler.php?id=5&lt;br /&gt;&lt;br /&gt;bunun gibi durumlardada id yi kontrol ettirerek injection ve xss &amp;#246;nlenebilir. Bunun i&amp;#231;in ise benim kullandigim ve tavsiye ettigim y&amp;#246;ntem if ile kontrol ettirmektir.&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;$id=$_GET['id'];&lt;br /&gt;if($id){&lt;br /&gt;    if($id==null){&lt;br /&gt;    echo&amp;quot;&amp;lt;script&amp;gt;location='sayfa_yok.php'&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;;&lt;br /&gt;}else{&lt;br /&gt;   if(strpos($id,&amp;quot;',;&amp;quot;)){&lt;br /&gt;   echo&amp;quot;&amp;lt;script&amp;gt;location='sayfa_yok.php'&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;;&lt;br /&gt;}&lt;br /&gt;else{&lt;br /&gt;include&amp;quot;modules/db_sorgu.php&amp;quot;;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;}else{&lt;br /&gt;echo&amp;quot;&amp;lt;script&amp;gt;location='sayfa_yok.php'&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;;&lt;br /&gt;}&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;yukardaki kod ile injection ve xss korumasi yaptik adres &amp;#231;ubuguna bos deger girmeyi engeller, deger girilip girilmedigini kontrol eder. Deger girilmisse o degerde  ' , ; gibi ifadeleri arar o ifadeler varsa sayfa_yok.php ye y&amp;#246;nlendirir.&lt;br /&gt;eger temiz ise db_sorgu.php yi baglanir ve sorgu &amp;#231;alisir&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
</item>
<item>
  <title>Mtn&#45;B</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Mtn&#45;B</author>
  <pubDate>Per, 04 Mar 2010 11:17:37 +0200</pubDate>
  <description>           &amp;lt;?php&lt;br /&gt;$text = &amp;quot;hi’ or ’a’=’a &amp;quot;;&lt;br /&gt;$new_text = str_replace(array('/','#','admin','or','=','and','-','(',')','[',']','|','&amp;amp;',' '),&amp;quot;&amp;quot;,$text);&lt;br /&gt;echo $new_text;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;hocam bu isime yaradi tesekk&amp;#252;ler...</description>
</item>
<item>
  <title>g&#252;ven</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>g&#252;ven</author>
  <pubDate>Sal, 26 Oca 2010 21:36:42 +0200</pubDate>
  <description>           @ADONEX veya senin deyiminle 'real asp coder'&lt;br /&gt;&lt;br /&gt;Yazdigin fonksiyonun sa&amp;#231;maliginin farkindamisin?&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Private Function x_injection(x)&lt;br /&gt;if isnumeric(x)=true then&lt;br /&gt;x_injection=true&lt;br /&gt;else&lt;br /&gt;x_injection=false&lt;br /&gt;end if&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;if x_injection(id)=false then response.Redirect(&amp;quot;index.asp?error=hataaaa&amp;quot;) &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;en sondaki satir yerine &lt;br /&gt;&lt;br /&gt;if isnumeric(id)=false then: response.redirect(&amp;quot;numerikdegil.asp&amp;quot;) &lt;br /&gt;&lt;br /&gt;yazarsan ayni islemi yapmis olursun, bu da fonksiyona gerek olmadigini g&amp;#246;sterir&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;&lt;br /&gt;ayrica s&amp;#246;yledigin sekilde kesin &amp;#231;&amp;#246;z&amp;#252;m degil malesef. id gerektiren islemler de evet ancak form girislerinde hayir&lt;img src=&quot;/mg/smilies/wink.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;;)&quot; /&gt;&lt;br /&gt;</description>
</item>
<item>
  <title>php inspector</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>php inspector</author>
  <pubDate>Çar, 09 Eyl 2009 23:48:42 +0200</pubDate>
  <description>           bos isler bunlar, mutlaka bir a&amp;#231;ik birakabilirsiniz, en dogrusu hazir php frameworklarindan yararlanmaktir.&lt;br /&gt;&lt;br /&gt;pear.php.net&lt;br /&gt;cakephp.org&lt;br /&gt;codeigniter.com&lt;br /&gt;&lt;br /&gt;yukaridaki sitelerde benim kullandigim ve tavsiye ettigim php frameworklari bulabilirsiniz.</description>
</item>
<item>
  <title>Kaan</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Kaan</author>
  <pubDate>Sal, 02 Haz 2009 20:49:42 +0200</pubDate>
  <description>           Sha512 gibi bir g&amp;#252;zellik elimizdeyken nasil olur da kirilmis md5'in en iyi oldugunu d&amp;#252;s&amp;#252;nebiliriz, bu garip.&lt;br /&gt;Sha512 ile sifreliyorum ve veritabaninda fazla yer kaplamasin diye md5 ile takrar sifreliyorum.</description>
</item>
<item>
  <title>Kaan</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Kaan</author>
  <pubDate>Sal, 02 Haz 2009 07:55:38 +0200</pubDate>
  <description>           Arkadaslar, sql'de id gibi parametreleri ister istemez querystring ile g&amp;#246;nderiyoruz ama gelen degerin numerik olup olmadigini kontrol etmeniz dahi b&amp;#252;t&amp;#252;n k&amp;#246;t&amp;#252; niyetli denemeleri etkisiz kilacaktir diye d&amp;#252;s&amp;#252;n&amp;#252;yorum.&lt;br /&gt;&lt;br /&gt;Mesela&lt;br /&gt;int ID;&lt;br /&gt;int.TryParse(Regex.Replace(Request.Url.Query, @&amp;quot;^\?id=(\d+)$&amp;quot;,&amp;quot;$1&amp;quot;), out ID);&lt;br /&gt;</description>
</item>
<item>
  <title>dijeo</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>dijeo</author>
  <pubDate>Per, 12 Mar 2009 02:15:33 +0200</pubDate>
  <description>           PHP i&amp;#231;in;&lt;br /&gt;htmlspecialchars(); ve addslashes(); , stripslashes(); gibi fonksiyonlari kullanmanin yeterli olacagini d&amp;#252;s&amp;#252;n&amp;#252;yorum. Sifre bilgilerini kripto ile koruma konusunda ise md5'den daha gelismis bi versiyon olan sha1 kullanilmali. ASP de var mi bilmiyorum ama PHP de mevcut. Artik pek &amp;#231;ok server sha1 destegi sunuyor.</description>
</item>
<item>
  <title>Salih</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Salih</author>
  <pubDate>Cmt, 20 Ara 2008 19:21:26 +0200</pubDate>
  <description>           S&amp;#246;yle bir hata buldum bu bir sql injection mudur? Nasil degerlendirebilirim? Tesekk&amp;#252;rler.:&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers hata '80040e14'&lt;br /&gt;&lt;br /&gt;[MySQL][ODBC 3.51 Driver][mysqld-5.0.45-community-nt]You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '=&amp;lt;% Response.Redirect &amp;quot;www.google.com&amp;quot; %&amp;gt; and numara=&amp;lt;% Response.Redirect &amp;quot;www.g' at line 1&lt;br /&gt;&lt;br /&gt;C:\INETPUB\VHOSTS\***********\HTTPDOCS\../../*****/8.asp, satir 42 &lt;br /&gt;</description>
</item>
<item>
  <title>schwert</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>schwert</author>
  <pubDate>Per, 26 Haz 2008 23:58:26 +0200</pubDate>
  <description>           B.A.D listeyi vermis... a&amp;#231;igi kapatmak isterseniz sunun gib bir kod kullanmaniz b&amp;#252;y&amp;#252;k &amp;#246;l&amp;#231;&amp;#252;de isinize yarayacaktir... kod php kodudur asp ye uyarlayabilirsiniz...&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;$text = &amp;quot;hi’ or ’a’=’a &amp;quot;;&lt;br /&gt;$new_text = str_replace(array('/','#','admin','or','=','and','-','(',')','[',']','|','&amp;amp;',' '),&amp;quot;&amp;quot;,$text);&lt;br /&gt;echo $new_text;&lt;br /&gt;?&amp;gt;</description>
</item>
<item>
  <title>Emre</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Emre</author>
  <pubDate>Pzt, 09 Haz 2008 21:39:14 +0200</pubDate>
  <description>           C# da yazdigimizi varsayarsak ... bir command object i edinelim &lt;br /&gt;&lt;br /&gt;using(cmd = connection.createcommand()){&lt;br /&gt;cmd.CommandText = &amp;quot;Select * From Whatever Where user=@user And pass=@pass&amp;quot;&lt;br /&gt;//sora bu @ ile belirtilen parametrelerin degerlerini verelim&lt;br /&gt;cmd.Parameters.Add(&amp;quot;@user&amp;quot;, SqlDBType.Int);&lt;br /&gt;cmd.Parameters[&amp;quot;@user&amp;quot;].Value = _usernameitasiyandegiskenim //string yada textbox.text yada querystring herneyse&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;simdi bu secure enough mi yoksa bunada &amp;#231;are bulundumu sevgili kevin mitnickler : ) saygilarimi sunarim kolay gelsin hepinize&lt;br /&gt;</description>
</item>
<item>
  <title>slayerdark</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>slayerdark</author>
  <pubDate>Cum, 16 Kas 2007 17:46:56 +0200</pubDate>
  <description>           sql komutlarini bilmeyen g&amp;#252;venlik&amp;#231;i arkadaslar acaba hackerana ya mi &amp;#246;zenip geldiniz buraya yoksa g&amp;#252;venliginizi saglamak i&amp;#231;in arastirma yaparkenmi ehehe bu arada bunlar artik yeni s&amp;#252;r&amp;#252;m apachelerde bi ise yaramazlar bosa ugrasmayin zaten yiyecek bi site bulursanizda egonuzu tatmin ederse o sizin zavalliliginizdir&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;</description>
</item>
<item>
  <title>ramazan</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>ramazan</author>
  <pubDate>Sal, 13 Kas 2007 14:02:05 +0200</pubDate>
  <description>           sql  komutlarini bulabilirmisiniz . bulursaniz memnun olurum   kib </description>
</item>
<item>
  <title>ADONEX</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>ADONEX</author>
  <pubDate>Çar, 03 Eki 2007 14:34:58 +0200</pubDate>
  <description>           ' id ile islem yaparken sql injection a kesin &amp;#231;&amp;#246;z&amp;#252;m ! Bu g&amp;#252;venligi asla asamaz !&lt;br /&gt;id=45 ' burayi ilk &amp;#246;nce sayi ile test edin.sonra string yani herhengi bir kod ile ya da metin ile !  id=45  ve id=&amp;quot;senerrr&amp;quot;  gibi&lt;br /&gt;&lt;br /&gt;Private Function x_injection(x)&lt;br /&gt;	if isnumeric(x)=true then &lt;br /&gt;		x_injection=true&lt;br /&gt;	else&lt;br /&gt;		x_injection=false&lt;br /&gt;	end if&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if x_injection(id)=false then response.Redirect(&amp;quot;index.asp?error=hataaaa&amp;quot;) ' asp.dll bu kodu g&amp;#246;r&amp;#252;nce asagidakinileri yorumlamadan hemen index.asp ye gider&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;' id=&amp;quot;sener&amp;quot; burda false d&amp;#246;ner demek ki adam bizim id sorgumuza sql injection yapmistir.&lt;br /&gt;&lt;br /&gt;' id=45 burda true d&amp;#246;ner ve demek ki sadece sayi geliyor. islem yapilabilir.&lt;br /&gt;&lt;br /&gt;' code by :  miyasof@hotmail.com&lt;br /&gt;' real asp coder</description>
</item>
<item>
  <title>B&#46;A&#46;D&#46;</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>B&#46;A&#46;D&#46;</author>
  <pubDate>Sal, 17 Tem 2007 00:28:53 +0200</pubDate>
  <description>           Materyalist &amp;#252;zerime alinmiyorum ama baya bir muhalefetsin. injection anlamini sen biliyormusun? Yada sana XSS nedir yenirmi i&amp;#231;ilirmi diye mi sormaliyiz acaba. Sen en iyi html nedir onu s&amp;#246;yle&lt;br /&gt;&lt;br /&gt;bektasaykut senin sisteminde de injection uygulanir. Adindan da anlayacagin gibi bir yere enjekte etmekten geliyor. Yani sonucta sen sql inde bir sorgu veriyorsun. o sorgu nerden geliyor ? bir input tan. Sen inputtan gelen verini s&amp;#252;z&amp;#252;p filtrelemezsen yada encrypt etmezsen gelen sql injection kodunu, direkman olarak sql e g&amp;#246;nderiyorsun dogal olarak saldirgan senin belki sql ine direk sizamasa da yapisi hakkinda bilgi sahibi oluyor. D&amp;#252;s&amp;#252;n ki ben veritabaninda ki &amp;#252;yeler diye bir form oldugunu &amp;#246;grendim, id lerin Kimlik adinda ki bir tabloda oldugunu kullanici adinin da kadi adli bir tabloda oldugunu ve bunun gibi bir s&amp;#252;r&amp;#252; sey. Tabi diyeceksin ki e &amp;#246;grense ne olur?... Drop y&amp;#246;ntemi ile d&amp;#252;s&amp;#252;rebilir hepsini. Belki senin 10-100 -1000 tane &amp;#252;yen vardir sorn degil dersin ama farzetki yonja ne bileyim hepsiburada gibi bir veritabanin var ozman da da dikkat etmen lazim...&lt;br /&gt;&lt;br /&gt;SQL injection i&amp;#231;in kullanilan b&amp;#252;t&amp;#252;n komutlari veriyorum, kendi sistemlerinizde test edin. Oturun inceleyin hangi komutlar g&amp;#246;nderiliyor. Buna g&amp;#246;re fonksiyonlar yazin ve ayiklayin. Ama mutlaka !!! Mutlaka sifre islemlerini MD5 ile &amp;#231;evirin. Hemde 2 Kez..&lt;br /&gt;MD5(MD5(Request.form(&amp;quot;pass&amp;quot;))) &lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;&lt;br /&gt;admin’-- &lt;br /&gt;’ or 0=0 -- &lt;br /&gt;&amp;quot; or 0=0 -- &lt;br /&gt;or 0=0 -- &lt;br /&gt;’ or 0=0 # &lt;br /&gt;&amp;quot; or 0=0 # &lt;br /&gt;or 0=0 # &lt;br /&gt;’ or ’x’=’x &lt;br /&gt;&amp;quot; or &amp;quot;x&amp;quot;=&amp;quot;x &lt;br /&gt;’) or (’x’=’x &lt;br /&gt;’ or 1=1-- &lt;br /&gt;&amp;quot; or 1=1-- &lt;br /&gt;or 1=1-- &lt;br /&gt;’ or a=a-- &lt;br /&gt;&amp;quot; or &amp;quot;a&amp;quot;=&amp;quot;a &lt;br /&gt;’) or (’a’=’a &lt;br /&gt;&amp;quot;) or (&amp;quot;a&amp;quot;=&amp;quot;a &lt;br /&gt;hi&amp;quot; or &amp;quot;a&amp;quot;=&amp;quot;a &lt;br /&gt;hi&amp;quot; or 1=1 -- &lt;br /&gt;hi’ or 1=1 -- &lt;br /&gt;hi’ or ’a’=’a &lt;br /&gt;hi’) or (’a’=’a &lt;br /&gt;hi&amp;quot;) or (&amp;quot;a&amp;quot;=&amp;quot;a</description>
</item>
<item>
  <title>&#231;e&#231;en</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>&#231;e&#231;en</author>
  <pubDate>Cum, 13 Tem 2007 22:54:26 +0200</pubDate>
  <description>           hepsi bos &amp;#246;nemli olan o kodlari taraslamak linux bilmiyosaniz hi&amp;#231; ugrasmayin:)</description>
</item>
<item>
  <title>bektasaykut</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>bektasaykut</author>
  <pubDate>Per, 28 Haz 2007 19:46:42 +0200</pubDate>
  <description>           Dim Giris&lt;br /&gt;Set Giris = Kaynak.Execute(&amp;quot;Select deger from sifre where alan='sifre'&amp;quot;)&lt;br /&gt;If Giris(0)=Request.Form(&amp;quot;sifre&amp;quot;) Then&lt;br /&gt;Session(&amp;quot;oturum&amp;quot;) = &amp;quot;xxx&amp;quot;&lt;br /&gt;Else&lt;br /&gt;If Session(&amp;quot;oturum&amp;quot;) &amp;lt;&amp;gt; &amp;quot;xxx&amp;quot; Then&lt;br /&gt;Response.Write(&amp;quot;Sifre yanlis : &amp;quot;&amp;amp;Request.Form(&amp;quot;sifre&amp;quot;))&lt;br /&gt;End If&lt;br /&gt;End If&lt;br /&gt;/////&lt;br /&gt;Burada sql injection uygulanabilir mi sizce? &lt;br /&gt;Kendi sistemimdeki kodlar bunlar</description>
</item>
<item>
  <title>sdll</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>sdll</author>
  <pubDate>Cum, 22 Haz 2007 02:06:57 +0200</pubDate>
  <description>           SELECT * FROM Members WHERE Username = 'teyyare.. sallama ne yazarsan yaz ' AND Password= '' OR ''=''     &lt;br /&gt;&lt;br /&gt;kullanci adi ve siifresine ayni seyi yazmaya gerek yok biri yeterlii olur. ama nedendir &amp;#231;akamadim.. Ayrintili bi sekilde anlatirsa birisi &amp;#231;ok iyi olur tabi anlayan var ise dernlemsine...</description>
</item>
<item>
  <title>Materyalist</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Materyalist</author>
  <pubDate>Sal, 12 Haz 2007 19:46:34 +0200</pubDate>
  <description>           Acaba Buraya Yorum Yazanlardan Ka&amp;#231; Kisi &amp;quot;INJECTION&amp;quot; Kelimesinin Tam Olarak Ne Anlama Geldigini Biliyor?</description>
</item>
<item>
  <title>impale</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>impale</author>
  <pubDate>Sal, 30 Oca 2007 14:35:34 +0200</pubDate>
  <description>           sql ile ilgili bir &amp;#231;alisma ariyordum bu siteyi g&amp;#246;rd&amp;#252;m..&lt;br /&gt;yararli bilgiler var. herkese kolay gelsin...</description>
</item>
<item>
  <title>answer</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>answer</author>
  <pubDate>Cum, 26 Oca 2007 18:11:34 +0200</pubDate>
  <description>           sitenize yeni bakiyorum ve acayip merak lisiyim bana yardimci olursaniz sevi nirim bunlari daha kolay ve acik nasil ogrenebilirim bana ce vap verirseniz sevinirim simdiden tesekkurler yazilarinizi takip edicem</description>
</item>
<item>
  <title>C4N&#95;P0L4T</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>C4N&#95;P0L4T</author>
  <pubDate>Sal, 23 Oca 2007 13:08:32 +0200</pubDate>
  <description>           Bende Yeni Basladim Okuyorum Yazdiklarinizi Anlamadan Cok Begendim Bana Biraz Yardim Edip Yonlendirirseniz Sevinirim.Yani Nasil Baslicam Gibi Tesekk&amp;#252;rler.</description>
</item>
<item>
  <title>kuen</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>kuen</author>
  <pubDate>Sal, 23 Oca 2007 11:22:06 +0200</pubDate>
  <description>           sql injection dan korunuyoruzda, xss den tam g&amp;#252;venli bir sekilde nasil korunuruzu bende uzun zamandir d&amp;#252;s&amp;#252;n&amp;#252;yorum, makaleni merakla bekliyorum ferruh.</description>
</item>
<item>
  <title>Varol</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Varol</author>
  <pubDate>Paz, 21 Oca 2007 15:56:05 +0200</pubDate>
  <description>           evet zaten replace ederek kullaniyorum query stringleri fakat bu y&amp;#246;ntemde en azindan adami ugrastirir diye aklima geldi&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; yani madem girdin hemencecik m&amp;#252;d&amp;#252;r&amp;#252;n odasina dalma ilk &amp;#246;nce giris katta dur demek&lt;img src=&quot;/mg/smilies/grin.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:D&quot; /&gt;</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Paz, 21 Oca 2007 14:12:53 +0200</pubDate>
  <description>           &lt;blockquote&gt;Benim xss den kastim sonu&amp;#231;ta yine bu yolla, stringler ile verinin aktarilmasiydi. Yani &amp;#246;nemli olan o stringlerin, formlarin i&amp;#231;erisi tarafindan tanimsiz kalmasini saglamak, bunu s&amp;#246;ylemek istedim&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;/blockquote&gt;&lt;br /&gt;Hicbir koruma olmamasindan kat kat iyidir&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;</description>
</item>
<item>
  <title>B&#46;A&#46;D&#46;</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>B&#46;A&#46;D&#46;</author>
  <pubDate>Paz, 21 Oca 2007 01:44:27 +0200</pubDate>
  <description>           Benim xss den kastim sonu&amp;#231;ta yine bu yolla, stringler ile verinin aktarilmasiydi. Yani &amp;#246;nemli olan o stringlerin, formlarin i&amp;#231;erisi tarafindan tanimsiz kalmasini saglamak, bunu s&amp;#246;ylemek istedim&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Paz, 21 Oca 2007 00:25:19 +0200</pubDate>
  <description>           &lt;blockquote&gt;Unutmayin ki XSS ataklarda var.. &lt;/blockquote&gt;&lt;br /&gt;Su anki konu ile tamamen alakasiz olmasinin yaninda kullandiginiz korunma koduna guvenmeniz buyuk bir hata lakin XSS ten korunmak icin en kotu yollardan biri o sekilde basir bir blacklisting yapmak. Sadece olurda birileri buradan alip kullanir diye yazayim dedim.&lt;br /&gt;&lt;br /&gt;Ileride XSS konusuna da gelecegiz orada insallah detaylarina ineriz.&lt;br /&gt;&lt;br /&gt;Simdilik `Server.HTMLEncode()` u kulanmaniz yukaridakine gore daha saglikli.</description>
</item>
<item>
  <title>B&#46;A&#46;D&#46;</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>B&#46;A&#46;D&#46;</author>
  <pubDate>Cmt, 20 Oca 2007 23:47:35 +0200</pubDate>
  <description>           okadar da basite almayin bunu... Unutmayin ki XSS ataklarda var.. Bunun i&amp;#231;in ben asp girislerimde bunu gibi bir fonksiyon kullaniyorum. Bunun ile sizde korunaiblirsiniz..&lt;br /&gt;&lt;br /&gt;		Function PostKontrol(yazi)&lt;br /&gt;		&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;&amp;lt;&amp;quot;, &amp;quot;&amp;amp;lt;&amp;quot;)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;&amp;gt;&amp;quot;, &amp;quot;&amp;amp;gt;&amp;quot;)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;script&amp;quot;, &amp;quot;&amp;amp;#115;cript&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;SCRIPT&amp;quot;, &amp;quot;&amp;amp;#083;CRIPT&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Script&amp;quot;, &amp;quot;&amp;amp;#083;cript&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;script&amp;quot;, &amp;quot;&amp;amp;#083;cript&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;object&amp;quot;, &amp;quot;&amp;amp;#111;bject&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;OBJECT&amp;quot;, &amp;quot;&amp;amp;#079;BJECT&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Object&amp;quot;, &amp;quot;&amp;amp;#079;bject&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;object&amp;quot;, &amp;quot;&amp;amp;#079;bject&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;applet&amp;quot;, &amp;quot;&amp;amp;#097;pplet&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;APPLET&amp;quot;, &amp;quot;&amp;amp;#065;PPLET&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Applet&amp;quot;, &amp;quot;&amp;amp;#065;pplet&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;applet&amp;quot;, &amp;quot;&amp;amp;#065;pplet&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;embed&amp;quot;, &amp;quot;&amp;amp;#101;mbed&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;EMBED&amp;quot;, &amp;quot;&amp;amp;#069;MBED&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Embed&amp;quot;, &amp;quot;&amp;amp;#069;mbed&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;embed&amp;quot;, &amp;quot;&amp;amp;#069;mbed&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;event&amp;quot;, &amp;quot;&amp;amp;#101;vent&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;EVENT&amp;quot;, &amp;quot;&amp;amp;#069;VENT&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Event&amp;quot;, &amp;quot;&amp;amp;#069;vent&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;event&amp;quot;, &amp;quot;&amp;amp;#069;vent&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;document&amp;quot;, &amp;quot;&amp;amp;#100;ocument&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;DOCUMENT&amp;quot;, &amp;quot;&amp;amp;#068;OCUMENT&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Document&amp;quot;, &amp;quot;&amp;amp;#068;ocument&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;document&amp;quot;, &amp;quot;&amp;amp;#068;ocument&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;cookie&amp;quot;, &amp;quot;&amp;amp;#099;ookie&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;COOKIE&amp;quot;, &amp;quot;&amp;amp;#067;OOKIE&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Cookie&amp;quot;, &amp;quot;&amp;amp;#067;ookie&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;cookie&amp;quot;, &amp;quot;&amp;amp;#067;ookie&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;form&amp;quot;, &amp;quot;&amp;amp;#102;orm&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;FORM&amp;quot;, &amp;quot;&amp;amp;#070;ORM&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;Form&amp;quot;, &amp;quot;&amp;amp;#070;orm&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;form&amp;quot;, &amp;quot;&amp;amp;#070;orm&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;on&amp;quot;, &amp;quot;&amp;amp;#111;n&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;ON&amp;quot;, &amp;quot;&amp;amp;#079;N&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;On&amp;quot;, &amp;quot;&amp;amp;#079;n&amp;quot;, 1, -1, 0)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;on&amp;quot;, &amp;quot;&amp;amp;#111;n&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;document.cookie&amp;quot;, &amp;quot;&amp;amp;#068;ocument.cookie&amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;javascript:&amp;quot;, &amp;quot;javascript &amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;vbscript:&amp;quot;, &amp;quot;vbscript &amp;quot;, 1, -1, 1)&lt;br /&gt;				yazi = Replace(yazi, &amp;quot;'&amp;quot;, &amp;quot;&amp;quot;)&lt;br /&gt;				yazi = Replace(yazi, vbCrLf, &amp;quot;&lt;br&gt;&amp;quot;)&lt;br /&gt;			&lt;br /&gt;			PostKontrol = yazi&lt;br /&gt;		&lt;br /&gt;		End Function&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kullanmak i&amp;#231;in ise requestin basina PostKontrol yapin yeter.&lt;br /&gt;&lt;br /&gt;&amp;#214;rnegin;&lt;br /&gt;&lt;br /&gt;kadi = PostKontrol(Reques.Form(&amp;quot;UserName&amp;quot;))&lt;br /&gt;&lt;br /&gt;gibi. Sifre i&amp;#231;inde herzaman kripto yapin. MD5 en iyisi. Takilan arkadaslkar olursa mail atabilirler microsoft.turkey[at]gmail.com&lt;/br&gt;-FIXED&lt;/br&gt;-FIXED</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Cmt, 20 Oca 2007 22:59:14 +0200</pubDate>
  <description>           &lt;blockquote&gt;zaman db yapimizda ilk &amp;#252;yeyi herzaman en az yetkiyi vermeliyiz. Veya aklima simdi geldi. Bir if daha ekleyip &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Aslinda hayir bu bir korunma degil hala SQL Injection a tamamen acikcisiniz, bir cok acidan. SQL Injection dan korunmak temel olarak cok basit ASP icin konusursak tek tirnagi iki cirft tirnak ile replace etmek yeterli olacaktir. Ancak biraz daha detayli korunma makalesi de yoldaki makalelerden.</description>
</item>
<item>
  <title>Varol</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>Varol</author>
  <pubDate>Cmt, 20 Oca 2007 22:12:33 +0200</pubDate>
  <description>           o zaman db yapimizda ilk &amp;#252;yeyi herzaman en az yetkiyi vermeliyiz. Veya aklima simdi geldi. Bir if daha ekleyip &lt;br /&gt;&lt;br /&gt;if memberID=1 then&lt;br /&gt;Response.Redirect &amp;quot;/error.asp&amp;quot;&lt;br /&gt;end if&lt;br /&gt;&lt;br /&gt;dersek en azindan adami biraz daha ugrastirmis olabiliriz. Pekala saldirgan db den sorgu yaptiramadigi s&amp;#252;rece ilk kullanici disinda herhangi biriyle login olamaz degilmi ?&lt;br /&gt;&lt;br /&gt;  Bu da az da olsa bir &amp;#246;nlem olabilir. ' or 1=1 -- gibi bir sistem kullanarak test ederdim ben login panelini yazdigimda pekde basarili olmazdim tabi.&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;&lt;br /&gt;Yazi &amp;#231;ok g&amp;#252;zel devamini bekliyoruz bloglarda tanitima basliyoruz. </description>
</item>
<item>
  <title>yLmZ</title>
  <link>http://ferruh.mavituna.com/sql-injection-a-giris-ve-sql-injection-nedir-oku/</link>
  <author>yLmZ</author>
  <pubDate>Cmt, 20 Oca 2007 09:57:40 +0200</pubDate>
  <description>           Benm yaptigim saftirik bir sitemde bu sql i kullanmistim,, anlasildi nasil girdikleri =)</description>
</item>

</channel>
</rss>
