|
|
|
Date Submitted:
06/17/05
Hits: 53 Rating: ![]() ![]() ![]() ![]() based on 0 votes
Detection of SQL Injection and Cross-site Scripting AttacksAdded by Papergrl
Description:
In the last couple of years, attacks against the Web application layer have required increased attention from security professionals. This is because no matter how strong your firewall rulesets are or how diligent your patching mechanism may be, if your Web application developers haven't followed secure coding practices, attackers will walk right into your systems through port 80. The two main attack techniques that have been used widely are SQL Injection [ref 1] and Cross Site Scripting [ref 2] attacks. SQL Injection refers to the technique of inserting SQL meta-characters and commands into Web-based input fields in order to manipulate the execution of the back-end SQL queries. These are attacks directed primarily against another organization's Web server. Cross Site Scripting attacks work by embedding script tags in URLs and enticing unsuspecting users to click on them, ensuring that the malicious Javascript gets executed on the victim's machine.
Read the Complete Paper You don't have permission to post replies. Please login or register. |
