International Conference and Workshop on Emerging Trends in Technology |
Foundation of Computer Science USA |
ICWET2012 - Number 9 |
March 2012 |
Authors: Shruti BangreRung, AlkaJaiswalRungt |
5fcf2c77-f873-4d7c-b559-4fcb157e86ec |
Shruti BangreRung, AlkaJaiswalRungt . Techniques ofSQL Injection Detectionand Prevention. International Conference and Workshop on Emerging Trends in Technology. ICWET2012, 9 (March 2012), 26-35.
SQLinjectionisatechniqueusedtoexploitwebapplications thatuseclient-supplied datainSQL querieswithoutvalidating the input. SQLinjectionis anattackmethodologythat targets the data residing ina database throughthe firewallthat shieldsit.TheSQLInjectionworkseveniftheSystem isfully patched,itrequires nothing butport80should open.Theattacktakesadvantageofpoorinputvalidationin code andwebsite administration.Researchers have proposed differenttoolstodetectandpreventthis vulnerability.In thispaperwe present SQLinjectionattacktypes andalsocurrent techniqueswhichcandetector preventtheseattacks.Finallywe evaluate these techniques