Hacking Prevention Using Positive Tainting
Abstract
Web applications computer programs allowing website visitors to submit louis vuitton väska rea and retrieve data to/from a database over the Internet using their preferred web browser. Web application provides flexibility, interoperability, availability, because of these reasons they are more prone to web-based attacks. One of such attack includes SQL injection, A SQL injection is often used to attack the security of a website by inputting SQL statements in a web form. This has become increasingly frequent and more serious. This paper includes a new approach for protecting web application against SQL injection. The approach is based on concept of positive tainting, on character-level tainting and on the concept of syntax-aware evaluation. Web Application SQL-injection Preventer (WASP) tool is used to perform the evaluation.
Keywords SQL, Tree Validation, Tracing Data
Full Text