SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks

Securing the web against frequent cyber attacks is a big concern as attackers usually intend to snitch private information,financial information, deface and damages websites to prove their hacking capabilities. This type of vandalism may drive many corporations that conduct their business through th...

Full description

Bibliographic Details
Main Authors: Mat Ali, Abdul Bashah, Shakhatreh, Yaseen Ibrahim Ala’, Mohd Abdullah, Syazwan, Alostad, Jasem
Format: Article
Language:English
Published: Elsevier Ltd. 2011
Subjects:
Online Access:https://repo.uum.edu.my/id/eprint/4455/1/SQL-.pdf
_version_ 1825740321014677504
author Mat Ali, Abdul Bashah
Shakhatreh, Yaseen Ibrahim Ala’
Mohd Abdullah, Syazwan
Alostad, Jasem
author_facet Mat Ali, Abdul Bashah
Shakhatreh, Yaseen Ibrahim Ala’
Mohd Abdullah, Syazwan
Alostad, Jasem
author_sort Mat Ali, Abdul Bashah
collection UUM
description Securing the web against frequent cyber attacks is a big concern as attackers usually intend to snitch private information,financial information, deface and damages websites to prove their hacking capabilities. This type of vandalism may drive many corporations that conduct their business through the web to suffer financial and reputation damages. One of the most dangerous cyber attacks is the Structured Query Language (SQL)-injection attack, whereby this type of attack can be launched through the web browsers. The vulnerability of SQL-injection attack can be attributed to inappropriate programming practice by the website developers, which leaves a lot of doors widely open for the attackers to exploit these and gaining access to confidential information that resides in the website server databases.In order to address this vulnerability, it must be feasible to detect the vulnerability and enhance the coding structure of the website to avoid being an easy victim to this type of cyber attacks.Detecting the SQL-injection vulnerability requires the development of a powerful tool that can automatically create SQLinjection attacks using efficient features (different attacking patters) to detect the vulnerability of the websites. This paper discuss the development of a new web scanning (MySQLlInjector) tool with enhanced features that will be able to conduct efficient penetration test on PHP (started as Personal Home Page but now widely used as Hypertext Preprocesses) based websites to detect SQL injection vulnerabilities. This tool will automate the penetration test process, to make it easy even for those who are not aware familiar about hacking techniques.
first_indexed 2024-07-04T05:25:05Z
format Article
id uum-4455
institution Universiti Utara Malaysia
language English
last_indexed 2024-07-04T05:25:05Z
publishDate 2011
publisher Elsevier Ltd.
record_format eprints
spelling uum-44552012-02-22T23:55:10Z https://repo.uum.edu.my/id/eprint/4455/ SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks Mat Ali, Abdul Bashah Shakhatreh, Yaseen Ibrahim Ala’ Mohd Abdullah, Syazwan Alostad, Jasem QA76 Computer software Securing the web against frequent cyber attacks is a big concern as attackers usually intend to snitch private information,financial information, deface and damages websites to prove their hacking capabilities. This type of vandalism may drive many corporations that conduct their business through the web to suffer financial and reputation damages. One of the most dangerous cyber attacks is the Structured Query Language (SQL)-injection attack, whereby this type of attack can be launched through the web browsers. The vulnerability of SQL-injection attack can be attributed to inappropriate programming practice by the website developers, which leaves a lot of doors widely open for the attackers to exploit these and gaining access to confidential information that resides in the website server databases.In order to address this vulnerability, it must be feasible to detect the vulnerability and enhance the coding structure of the website to avoid being an easy victim to this type of cyber attacks.Detecting the SQL-injection vulnerability requires the development of a powerful tool that can automatically create SQLinjection attacks using efficient features (different attacking patters) to detect the vulnerability of the websites. This paper discuss the development of a new web scanning (MySQLlInjector) tool with enhanced features that will be able to conduct efficient penetration test on PHP (started as Personal Home Page but now widely used as Hypertext Preprocesses) based websites to detect SQL injection vulnerabilities. This tool will automate the penetration test process, to make it easy even for those who are not aware familiar about hacking techniques. Elsevier Ltd. 2011 Article PeerReviewed application/pdf en https://repo.uum.edu.my/id/eprint/4455/1/SQL-.pdf Mat Ali, Abdul Bashah and Shakhatreh, Yaseen Ibrahim Ala’ and Mohd Abdullah, Syazwan and Alostad, Jasem (2011) SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks. Procedia Computer Science, 3. pp. 453-458. ISSN 18770509 http://dx.doi.org/10.1016/j.procs.2010.12.076 doi:10.1016/j.procs.2010.12.076 doi:10.1016/j.procs.2010.12.076
spellingShingle QA76 Computer software
Mat Ali, Abdul Bashah
Shakhatreh, Yaseen Ibrahim Ala’
Mohd Abdullah, Syazwan
Alostad, Jasem
SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title_full SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title_fullStr SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title_full_unstemmed SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title_short SQL-injection vulnerability scanning tool for automatic creation of SQL-injection attacks
title_sort sql injection vulnerability scanning tool for automatic creation of sql injection attacks
topic QA76 Computer software
url https://repo.uum.edu.my/id/eprint/4455/1/SQL-.pdf
work_keys_str_mv AT mataliabdulbashah sqlinjectionvulnerabilityscanningtoolforautomaticcreationofsqlinjectionattacks
AT shakhatrehyaseenibrahimala sqlinjectionvulnerabilityscanningtoolforautomaticcreationofsqlinjectionattacks
AT mohdabdullahsyazwan sqlinjectionvulnerabilityscanningtoolforautomaticcreationofsqlinjectionattacks
AT alostadjasem sqlinjectionvulnerabilityscanningtoolforautomaticcreationofsqlinjectionattacks