Outline

  • Abstract
  • Keywords
  • 1. Background
  • 2. Sql Injection Vulnerability Problems
  • 3. Sql Injector Tool Development Methodology
  • 4. Mysqlinjector Tool
  • 5. Conclusion and Future Work
  • References

رئوس مطالب

  • چکیده
  • 1. پس زمینه
  • 2. مسائل آسیب پذیری تزریق SQL
  • 3. متدولوژی توسعه ابزار تزریقگر SQL
  • 4. ابزار MySQLInjector
  • 5. نتیجه گیری و اثر آتی

Abstract

Securing the web against frequent cyber attacks is a big concern as attackers usually intend to snitch private information, financial information, deface and damages websites to prove their hacking capabilities. This type of vandalism may drive many corporations that conduct their business through the web to suffer financial and reputation damages. One of the most dangerous cyber attacks is the Structured Query Language (SQL)-injection attack, whereby this type of attack can be launched through the web browsers. The vulnerability of SQL-injection attack can be attributed to inappropriate programming practice by the website developers, which leaves a lot of doors widely open for the attackers to exploit these and gaining access to confidential information that resides in the website server databases. In order to address this vulnerability, it must be feasible to detect the vulnerability and enhance the coding structure of the website to avoid being an easy victim to this type of cyber attacks. Detecting the SQL-injection vulnerability requires the development of a powerful tool that can automatically create SQLinjection attacks using efficient features (different attacking patters) to detect the vulnerability of the websites. This paper discuss the development of a new web scanning (MySQLlInjector) tool with enhanced features that will be able to conduct efficient penetration test on PHP (started as Personal Home Page but now widely used as Hypertext Preprocesses) based websites to detect SQL injection vulnerabilities. This tool will automate the penetration test process, to make it easy even for those who are not aware familiar about hacking techniques.

Keywords: - -

5. Conclusion and Future Work

MySQLInjector is new scanning tool that is capable of conducting efficient penetration tests on PHP based websites to detect the hidden SQL vulnerabilities in web server databases. The tools has a combination of attacking patterns, vectors and modes that allows web developers that are illiterate about hacking techniques in conducting penetration testing on their web database servers. The future wok in this area involves expanding the tools capability in conducting penetration test on Active Server Pages (ASP), and Java Server Pages (JSP) based websites.

دانلود ترجمه تخصصی این مقاله دانلود رایگان فایل pdf انگلیسی