High Impact Factor : 4.396 icon | Submit Manuscript Online icon |

SQL Injection in Web Application

Author(s):

Vikas Keshavnath Tiwari , Department of MCA, Vivekanand Education Society Institute of Technology, Mumbai; Indira Bhattacharya, Department of MCA, Vivekanand Education Society Institute of Technology, Mumbai

Keywords:

SQL, WAF, HTTP or 443 SSL

Abstract

SQL Injection threat has full-grown to the purpose wherever currently we tend to square measure seeing weaponized SQL Injection attacks perpetrated by state actors. Organizations square measure frequently being broken via SQL Injection attacks that slip seamlessly through the firewall over port eighty (HTTP) or 443 (SSL) to soft internal networks and vulnerable databases. Sleuthing SQL statements injected into an online application has well-tried very difficult. There square measure many tacks organizations will take – interference, redress, and mitigation. Once implementing interference and redress efforts, the enterprise strives to develop secure code and/or cipher confidential information hold on within the info. However, these aren't continuously offered choices. For instance, in some cases the applications ASCII text file might are developed by a 3rd party and not be offered for modification. To boot, fixing deployed code needs important resources and time. Therefore, redaction associate existing operational application would want to be prioritized before comes driving new business. Similarly, efforts to cipher confidential information hold on within the info will take even longer and need additional resources. Given today’s compressed development cycles and also the restricted variety of developers with security domain expertise, even obtaining the code rewrite project off the bottom is usually a frightening task.

Other Details

Paper ID: IJSRDV5I41423
Published in: Volume : 5, Issue : 4
Publication Date: 01/07/2017
Page(s): 1521-1525

Article Preview

Download Article