SQL Injection in Web Application |
Author(s): |
| Vikas Keshavnath Tiwari , Department of MCA, Vivekanand Education Society Institute of Technology, Mumbai; Indira Bhattacharya, Department of MCA, Vivekanand Education Society Institute of Technology, Mumbai |
Keywords: |
| SQL, WAF, HTTP or 443 SSL |
Abstract |
|
SQL Injection threat has full-grown to the purpose wherever currently we tend to square measure seeing weaponized SQL Injection attacks perpetrated by state actors. Organizations square measure frequently being broken via SQL Injection attacks that slip seamlessly through the firewall over port eighty (HTTP) or 443 (SSL) to soft internal networks and vulnerable databases. Sleuthing SQL statements injected into an online application has well-tried very difficult. There square measure many tacks organizations will take – interference, redress, and mitigation. Once implementing interference and redress efforts, the enterprise strives to develop secure code and/or cipher confidential information hold on within the info. However, these aren't continuously offered choices. For instance, in some cases the applications ASCII text file might are developed by a 3rd party and not be offered for modification. To boot, fixing deployed code needs important resources and time. Therefore, redaction associate existing operational application would want to be prioritized before comes driving new business. Similarly, efforts to cipher confidential information hold on within the info will take even longer and need additional resources. Given today’s compressed development cycles and also the restricted variety of developers with security domain expertise, even obtaining the code rewrite project off the bottom is usually a frightening task. |
Other Details |
|
Paper ID: IJSRDV5I41423 Published in: Volume : 5, Issue : 4 Publication Date: 01/07/2017 Page(s): 1521-1525 |
Article Preview |
|
|
|
|
