Information Systems Security: 6th International Conference, ICISS 2010, Gandhinagar, India, December 17-19, 2010 - Security and Cryptology 6503

£40.49 New RRP £44.99 Save £4.50 (10%)

Condition: New

Seen it cheaper? Ask for a price match

Free UK delivery
Thu 15 Oct

Time until the order cutoff

Hours40 Minutes32 Seconds56
Delivery details

Royal Mail 2nd Class — Free

Dispatch — when it leaves us

The arrival date shown is calculated from the order cutoff and delivery days.

Full delivery information

Ask about this book

Keep up to six books on this device for 30 days. Prices and availability are checked when shown. Clear to remove the history and switch this off.

Free returns within 60 days

Description

2.1 Web Application Vulnerabilities Many web application vulnerabilities havebeenwell documented andthemi- gation methods havealso beenintroduced [1]. The most common cause ofthose vulnerabilities isthe insu?cient input validation. Any data originated from o- side of the program code, forexample input data provided by user through a web form, shouldalwaysbeconsidered malicious andmustbesanitized before use.SQLInjection, Remote code execution orCross-site Scriptingarethe very common vulnerabilities ofthattype [3]. Below isabrief introduction toSQL- jection vulnerability though the security testingmethodpresented in thispaper is not limited toit. SQLinjectionvulnerabilityallowsanattackertoillegallymanipulatedatabase byinjectingmalicious SQL codes into the values of input parameters of http requests sentto the victim web site. 1:Fig.1. An example of a program written in PHP which contains SQL Injection v- nerability Figure 1 showsaprogram that uses the database query function mysql query togetuserinformationcorrespondingtothe userspeci?edby the GETinput- rameterusername andthen printtheresultto the clientbrowser.Anormalhttp request with the input parameter username looks like "http://example.

com/ index.php?username=bob". The dynamically created database query at line2 is "SELECT * FROM users WHERE username='bob' AND usertype='user'". Thisprogram is vulnerabletoSQLInjection attacks because mysql query uses the input value of username without sanitizingmalicious codes. A malicious code can be a stringthatcontains SQL symbols ork- words.Ifan attacker sendarequest with SQL code ('alice'-') - jected "http://example.com/index.php?username=alice'-", the query becomes "SELECT* FROM users WHERE username='alice'--' AND usertype='user'".

Book details

  • Authors:,
  • Format:Paperback
  • Pages:261 Pages
  • Publication date:02 December 2010
  • Publisher:Springer-Verlag Berlin and Heidelberg GmbH & Co. KG
  • Language:English
  • ISBN10:3642177131
  • ISBN-13:9783642177132
Wirral BooksBook shopping & support

How can we help?

Find your next book, compare editions or get help with an order.

Sending a chat message shares it with our AI provider. We save conversations privately for 90 days to understand enquiries and improve support. Clearing this browser tab does not delete the saved record. Keep passwords and payment details out of chat. Privacy