Detection method of the second-order sql injection in web applications

10Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Web applications are threatened seriously by SQL injection attacks. Even though a number of methods and tools have been put forward to detect or prevent SQL injections, there is a lack of effective method for detecting second-order SQL injection which stores user inputs into the back-end database. This paper proposes a detecting solution that combines both static and dynamic methods for second-order SQL injection. This solution first analyzes source code to find out the vulnerable data item pair which probably has second-order SQL injection vulnerability and then transforms it into an effective test sequence. After that, test sequence and malicious inputs are combined together for testing. Assessment of this solution in four applications and practical use show its effectiveness in the detection of second-order SQL injection. © 2014 Springer International Publishing Switzerland.

Cite

CITATION STYLE

APA

Yan, L., Li, X., Feng, R., Feng, Z., & Hu, J. (2014). Detection method of the second-order sql injection in web applications. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8332 LNCS, pp. 154–165). Springer Verlag. https://doi.org/10.1007/978-3-319-04915-1_11

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free