Vulnerability Mitigation ofWeb Data Bases by Identification of SQL Blind Injection Based on Customer Request

Message:
Abstract:
In recent years, the "SQL Injection Attacks" are considered one of the serious threats for webapplication programs which somehow take advantage of data bases. These internet based attacks, inject the unwanted SQL into the data base through an input parameter. Various methods to prevent the intrusion of SQL injection attacks have been introduced, all of which are practical in the favor of the service provider and are involved with web application codes or data base inquiry codes. In this article, a new method to prevent the injection attacks, has been presented which involves the requests sent to the service provider in such a way as to prevent the web application programs by identifying that the user is sending an unwanted SQL and injecting it to the data base. Since the customer request towards the service provider at the exit point from the customer and the input from the service provider are accessible, the possibility of implementing this method at both of these points will be reviewed. A special kind of these attacks is called " SQL Blind Injection Attacks" which due to their being less reviewed, is especially condidered in this essay.
Language:
Persian
Published:
Passive Defense Quarterly, Volume:2 Issue: 2, 2011
Page:
45
magiran.com/p965140  
دانلود و مطالعه متن این مقاله با یکی از روشهای زیر امکان پذیر است:
اشتراک شخصی
با عضویت و پرداخت آنلاین حق اشتراک یک‌ساله به مبلغ 1,390,000ريال می‌توانید 70 عنوان مطلب دانلود کنید!
اشتراک سازمانی
به کتابخانه دانشگاه یا محل کار خود پیشنهاد کنید تا اشتراک سازمانی این پایگاه را برای دسترسی نامحدود همه کاربران به متن مطالب تهیه نمایند!
توجه!
  • حق عضویت دریافتی صرف حمایت از نشریات عضو و نگهداری، تکمیل و توسعه مگیران می‌شود.
  • پرداخت حق اشتراک و دانلود مقالات اجازه بازنشر آن در سایر رسانه‌های چاپی و دیجیتال را به کاربر نمی‌دهد.
In order to view content subscription is required

Personal subscription
Subscribe magiran.com for 70 € euros via PayPal and download 70 articles during a year.
Organization subscription
Please contact us to subscribe your university or library for unlimited access!