0Pricing
Secure Coding & OWASP Top 10 for Backend · Pelajaran

Mencegah Injeksi XML dan LDAP

Perluas pertahanan terhadap injeksi di luar SQL dan perintah ke XML (XXE) serta LDAP. Pelajari cara input yang tidak tepercaya merusak interpreter tersebut dan cara menetralisasinya.

Mencegah Injeksi XML dan LDAP adalah pelajaran Secure Coding & OWASP Top 10 for Backend gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Secure Coding & OWASP Top 10 for Backend, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

Injection Beyond SQL

You have seen SQL, command, and XSS injection. Any interpreter that mixes untrusted input with structure is at risk. Two often-missed backend targets are XML parsers and LDAP directories.

What Is XXE

XML External Entity (XXE) injection abuses XML parsers that resolve external entities. An attacker defines an entity that reads a local file or hits an internal URL.

<!DOCTYPE x [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<data>&xxe;</data>

What XXE Can Do

  • Read sensitive files from the server
  • Perform server-side request forgery to internal services
  • Cause denial of service via entity expansion

All from a parser feature most apps never need.

Disable External Entities

The core fix is to configure the parser to not resolve external entities or DTDs. This single setting closes XXE entirely.

factory.setFeature('http://apache.org/xml/features/disallow-doctype-decl', true);
factory.setExpandEntityReferences(false);

Prefer Safer Formats

Where possible, accept JSON instead of XML — it has no entity concept and no equivalent attack. If you must take XML, lock the parser down first.

What Is LDAP Injection

LDAP directories are queried with filter strings. If user input is concatenated into a filter, an attacker can alter the query logic — the LDAP analog of SQL injection.

// vulnerable: input goes straight into the filter
filter = '(uid=' + username + ')'

An LDAP Bypass

Submitting * or admin)(&) as a username can turn a precise filter into one that matches many entries or always succeeds, bypassing authentication.

Escape LDAP Special Characters

Neutralize the special characters * ( ) \ NUL by escaping them before they enter a filter.

def escape(s):
    out = ''
    for ch in s:
        if ch in '*()\\':
            out += '\\' + format(ord(ch), '02x')
        else:
            out += ch
    return out

Use Parameterized APIs

Best of all, use directory APIs that accept inputs as parameters rather than building filter strings by hand — the same principle that makes prepared SQL statements safe.

The Common Defense

Across SQL, command, XML, and LDAP the rule is identical: never let untrusted input change the structure of a query or document. Separate code from data with parameterization, escaping, or safe parser config.

Allow-List Validation

Add a layer of defense by validating input against an allow-list of acceptable values before it reaches any interpreter. Rejecting unexpected characters or formats early shrinks the attack surface for every injection class at once.

import re
if not re.fullmatch(r'[a-zA-Z0-9_.-]+', username):
    raise ValueError('invalid username')

Quick Check

Test your injection defense.

Recap

You extended injection defense to XML and LDAP:

  • XXE abuses external entities — disable DTDs and entity resolution
  • LDAP injection manipulates filters — escape special characters or use parameterized APIs
  • The universal rule: keep untrusted data out of structure

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Mencegah Injeksi XML dan LDAP” gratis?

Ya — teks lengkap “Mencegah Injeksi XML dan LDAP” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Secure Coding & OWASP Top 10 for Backend, upgrade ke CoddyKit PRO. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Mencegah Injeksi XML dan LDAP”?

Perluas pertahanan terhadap injeksi di luar SQL dan perintah ke XML (XXE) serta LDAP. Pelajari cara input yang tidak tepercaya merusak interpreter tersebut dan cara menetralisasinya. Kamu berlatih Secure Coding & OWASP Top 10 for Backend dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Secure Coding & OWASP Top 10 for Backend?

Tidak diperlukan pengalaman sebelumnya. Secure Coding & OWASP Top 10 for Backend di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.

Berapa lama pelajaran “Mencegah Injeksi XML dan LDAP” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Secure Coding & OWASP Top 10 for Backend ini?

Ya. Setiap pelajaran Secure Coding & OWASP Top 10 for Backend menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Pencegahan Injeksi SQL
  2. Injeksi Perintah dan Kode
  3. Cross-Site Scripting (XSS) di Backend
  4. Mencegah Injeksi XML dan LDAP
← Kembali ke Secure Coding & OWASP Top 10 for Backend