| International Conference and Workshop on Emerging Trends in Technology |
| Foundation of Computer Science USA |
| ICWET2012 - Number 9 |
| March 2012 |
| Authors: Shruti BangreRung, AlkaJaiswalRungt |
Shruti BangreRung, AlkaJaiswalRungt . Techniques ofSQL Injection Detectionand Prevention. International Conference and Workshop on Emerging Trends in Technology. ICWET2012, 9 (March 2012), 26-35.
SQLinjectionisatechniqueusedtoexploitwebapplications thatuseclient-supplied datainSQL querieswithoutvalidating the input. SQLinjectionis anattackmethodologythat targets the data residing ina database throughthe firewallthat shieldsit.TheSQLInjectionworkseveniftheSystem isfully patched,itrequires nothing butport80should open.Theattacktakesadvantageofpoorinputvalidationin code andwebsite administration.Researchers have proposed differenttoolstodetectandpreventthis vulnerability.In thispaperwe present SQLinjectionattacktypes andalsocurrent techniqueswhichcandetector preventtheseattacks.Finallywe evaluate these techniques