Secure Coding & OWASP Top 10 for Backend · Pelajaran

Strategi Validasi Input Menyeluruh

Kembangkan rutin validasi input yang tangguh, termasuk pembuatan daftar izin, kanonikalisasi, dan penegakan tipe data secara ketat untuk menetralkan berbagai serangan berbasis input.

Pelajaran 2 dari 411 langkah

Strategi Validasi Input Menyeluruh adalah pelajaran Secure Coding & OWASP Top 10 for Backend gratis di CoddyKit. Ini adalah pelajaran 2 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Secure Coding & OWASP Top 10 for Backend, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

Why Validate Input?

Input validation is the process of ensuring that data provided by a user or another system conforms to expected formats and constraints.

It's your first and most critical line of defense against many types of attacks, like injection, buffer overflows, and even simple logic errors.

Always assume external input is malicious until proven otherwise!

Whitelisting for Safety

When validating input, the safest approach is whitelisting. This means you define what is explicitly allowed, and reject everything else.

  • Whitelisting: "Only these characters/patterns are allowed."
  • Blacklisting: "These characters/patterns are forbidden."

Blacklisting is dangerous because attackers often find ways around forbidden patterns. Whitelisting is proactive and far more secure.

Simple Whitelist Check

Here's a simple Java example of whitelisting allowed characters for a username. Only letters, numbers, and underscore are permitted.

public class InputValidator {
  public static boolean isValidUsername(String username) {
    if (username == null || username.isEmpty()) {
      return false;
    }
    // Whitelist: only letters, numbers, and underscore
    return username.matches("^[a-zA-Z0-9_]+$");
  }

  public static void main(String[] args) {
    String user1 = "coddy_kit_123";
    String user2 = "bad user!";
    String user3 = "admin";

    System.out.println("User '" + user1 + "' is valid: " + isValidUsername(user1));
    System.out.println("User '" + user2 + "' is valid: " + isValidUsername(user2));
    System.out.println("User '" + user3 + "' is valid: " + isValidUsername(user3));
  }
}

Normalize Your Inputs

Canonicalization (or normalization) is the process of converting input data into a standard, simplified, or "canonical" form before validation.

This is crucial because attackers often try to bypass validation by encoding input in different ways (e.g., %2F for /, & for &). Canonicalization ensures all variations are reduced to a common representation.

Canonicalization in Action

This Java snippet shows how you might canonicalize a path by decoding URL encoding and simplifying path components (e.g., removing /./ or /../ if allowed, though typically ../ should be blocked).

import java.net.URLDecoder;
import java.nio.charset.StandardCharsets;

public class PathCanonicalizer {
  public static String canonicalizePath(String path) {
    try {
      // 1. URL Decode the path
      String decodedPath = URLDecoder.decode(path, StandardCharsets.UTF_8.name());
      
      // 2. Normalize path separators (e.g., replace backslashes with forward slashes)
      decodedPath = decodedPath.replace("\\", "/");
      
      // 3. Remove redundant path elements (e.g., /./)
      decodedPath = decodedPath.replace("/./", "/");
      
      // Note: Full path traversal prevention requires more complex logic
      // and often involves resolving the path against a base directory.
      
      return decodedPath;
    } catch (Exception e) {
      return null; // Handle decoding errors
    }
  }

  public static void main(String[] args) {
    String input1 = "/usr/local/%2E%2E/etc/passwd";
    String input2 = "/app/data/./report.txt";

    System.out.println("Original: " + input1 + "\nCanonical: " + canonicalizePath(input1));
    System.out.println("\nOriginal: " + input2 + "\nCanonical: " + canonicalizePath(input2));
  }
}

Enforce Data Types

Beyond character sets, validating the data type of input is essential. If you expect an integer, ensure it's an integer. If you expect a boolean, ensure it's true or false.

Incorrect data types can lead to:

  • Application crashes
  • Unexpected behavior
  • Security vulnerabilities (e.g., type juggling attacks in some languages)

Type Check Example

This Java example demonstrates how to parse a string into an integer safely, catching potential NumberFormatExceptions.

public class DataTypeEnforcer {
  public static Integer parseIntegerSafely(String input) {
    if (input == null || input.trim().isEmpty()) {
      return null; // Or throw an IllegalArgumentException
    }
    try {
      return Integer.parseInt(input.trim());
    } catch (NumberFormatException e) {
      System.err.println("Error: '" + input + "' is not a valid integer.");
      return null; // Indicate failure
    }
  }

  public static void main(String[] args) {
    String validNum = "12345";
    String invalidNum = "abc";
    String negativeNum = "-50";

    System.out.println("Parsed '" + validNum + "': " + parseIntegerSafely(validNum));
    System.out.println("Parsed '" + invalidNum + "': " + parseIntegerSafely(invalidNum));
    System.out.println("Parsed '" + negativeNum + "': " + parseIntegerSafely(negativeNum));
  }
}

Limit & Format

Input validation also includes checking the length and format of data:

  • Length Validation: Prevent excessively long inputs that could cause buffer overflows or denial-of-service attacks. Set minimum and maximum lengths.
  • Format Validation: Use regular expressions (regex) to ensure input matches specific patterns, like email addresses, phone numbers, or UUIDs.

Combine these with whitelisting for robust checks.

Server-Side is Key

Remember, client-side validation (in the browser) is only for user experience. Attackers can easily bypass it.

All critical input validation must occur on the server-side. This ensures that even if a malicious user bypasses client-side checks, your backend remains secure.

Never trust input coming from the client!

Validate Your Knowledge

Which of the following are recommended best practices for comprehensive input validation?

Summary of Validation

In this lesson, we explored comprehensive input validation strategies:

  • Always use whitelisting to define what's allowed.
  • Perform canonicalization to normalize input and defeat encoding tricks.
  • Enforce strict data types to prevent unexpected behavior.
  • Validate length and format using regex.
  • Crucially, always perform validation on the server-side.

Robust input validation is a cornerstone of secure backend development!

Gratis untuk memulai

Belajar Secure Coding & OWASP Top 10 for Backend dengan tutor AI — gratis

Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.

Kursus
12
Pelajaran
48

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Strategi Validasi Input Menyeluruh” gratis?

Ya — teks lengkap “Strategi Validasi Input Menyeluruh” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Secure Coding & OWASP Top 10 for Backend, upgrade ke CoddyKit PRO. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Strategi Validasi Input Menyeluruh”?

Kembangkan rutin validasi input yang tangguh, termasuk pembuatan daftar izin, kanonikalisasi, dan penegakan tipe data secara ketat untuk menetralkan berbagai serangan berbasis input. Kamu berlatih Secure Coding & OWASP Top 10 for Backend dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Secure Coding & OWASP Top 10 for Backend?

Tidak diperlukan pengalaman sebelumnya. Secure Coding & OWASP Top 10 for Backend di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 2 dari 4.

Berapa lama pelajaran “Strategi Validasi Input Menyeluruh” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Secure Coding & OWASP Top 10 for Backend ini?

Ya. Setiap pelajaran Secure Coding & OWASP Top 10 for Backend menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Teknik SQLi dan NoSQLi Lanjutan
  2. Strategi Validasi Input Menyeluruh
  3. Content Security Policy (CSP) untuk Backend
  4. Mencegah Injeksi Perintah & LDAP
← Kembali ke Secure Coding & OWASP Top 10 for Backend