Author:
Hasan Pinky Tanzila,Ferdous Kaniz,Tasnim Jarin,Islam Kazi Shohaib
Abstract
SQL (Structured Query Language) injection represents a security weakness that enables attackers to run SQL commands within a web applications database. When exploiting a designed application lacking input validation a malicious actor can control input data to execute SQL queries. The objective of detecting SQL injection vulnerabilities is to identify any section of a web application to user input exploitation, for SQL injection attacks and confirm that the application adequately validates user inputs. The aim of this project is to try and form an attack chain and test the same against any website to assess the website for any weak links and identify any entry points that an attacker could use to penetrate the system and take control of the same. From the paper it is figured that most of the tools only check the vulnerability for the given URL and do not crawl through the webpages and find if the vulnerability is present in any of the other pages. In this project, we are taking the additional step to confirm that there are no vulnerabilities mentioned in this research present in any of the webpages.
Publisher
International Journal of Innovative Science and Research Technology
Reference40 articles.
1. Alde Alanda, D. S. (September 2021). Web Application Penetration Testing Using SQL Injection. International Journal On Informatics Visualization, 320-326.
2. Shobana R, D. M. (2020). A Thorough Study On SQL Injection Attack-Detection And Prevention Techniques And Research Issues. Journal of Information and Computational Science, 135-143.
3. Bandi Aruna, B. U. (2020). SQLID Framework In Order To Perceive SQL Injection Attack on Web Application. ICRAEM.
4. GitHub. (n.d.). sqlmapproject. Retrieved from GitHub: https://github.com/sqlmapproject/sqlmap
5. Invicti. (n.d.). SQL Injection Cheat Sheet. Retrieved from Invicti: https://www.invicti.com/blog/web-security/sql-injection-cheat-sheet/
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献