Web application security is a major concern due to the increasing threat of cyberattacks, especially SQL injection attacks, which threaten the integrity, confidentiality, and availability of data. This study aims to measure the vulnerability of web applications to SQL injection attacks using penetration testing methods. This test is carried out using a tool in the form of SQLMAP that can detect and exploit vulnerabilities through the boolean-based blind SQL injection technique and the error-based injection technique. In addition, this study also implements and tests the protection ability using the addlashes()- based input filtering method in PHP. The test results show that SQLMAP is widely used because protection against this vulnerability can provide a robust solution on how to protect web applications. That way, web applications are expected to be safe from attacks that damage existing data and systems
Copyrights © 2025