How to Patch Resolve Bug Bypass Admin

in utopian-io •  7 years ago  (edited)

A little tutorial to Resolve Bug SQL Injection in the form of admin login.
Previously I was telling how where a hacker who looks for loopholes through the Bypass Admin, which it uses code '=' 'or', maybe this code is often used by hackers who look for loopholes by way of bypass Admin. If a from login Admin which entered the following code will go to the dashboard or go to the admin page, then it is said Bug Admin SQL Injek. Because only use the following code without entering the original username.
Well now I will give you a little tutorial to prevent Bypass Admin, maybe my simple way below will provide little benefit for you and the Website is there to prevent malicious hackers.
Well, Previously you first check your scriptchek_login.php, for example like my script below that I will practice it.

This in MyScrip login.php
login.jpg

Once you see my script, it turns out the Script Bug here. because it does not have to inject preventive function.

login vlun.jpg

Of the script has not filtered the process of retrieving data from SQL inputted from the admin login, the use of filtering this so as not to ask a strange character, so as not to be processed. of the script has not filtered the process of retrieving data from SQL inputted from the admin login, the use of filtering this so as not to ask a strange character, so as not to be processed.

Create a function, here I use a function with the name 'injectpreventer':
Scrip
Screenshot_2.jpg

After we add the function will become script like below.

Screenshot_3.jpg

that's a very simple code to prevent Bug in Admin login process, the code is very simple to stay useful to overcome the hackers to get into our web, so thank you may be useful.



Posted on Utopian.io - Rewarding Open Source Contributors

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

@fadhilpurnahar, Like your contribution, upvote.

Your contribution cannot be approved because it does not follow the Utopian Rules. It is not a bug, and we accept only bugs in this category.

You can contact us on Discord.
[utopian-moderator]

Congratulations @fadhilpurnahar! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 1 year!

Click here to view your Board

Support SteemitBoard's project! Vote for its witness and get one more award!

Congratulations @fadhilpurnahar! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Vote for @Steemitboard as a witness to get one more award and increased upvotes!