Title Apsaugos nuo SQL injekcijų el.verslo svetainėse metodikos sudarymas ir tyrimas /
Translation of Title Development and research of method of protection against SQL injections in e-commerce websites.
Authors Ramoška, Aidas
Full Text Download
Pages 55
Keywords [eng] SQL injections ; database security ; e-business ; web application security
Abstract [eng] The target of SQL injection attack – interactive web programs, which use database servers. Those programs allow users to input information and as it is imputed, it forms SQL queries, which are sent into database server. With SQL injection help, the attacker using input fields forms harmful section of SQL query, which modifies previous query. Exploiting attack of SQL injection, the attacker may learn confidential information, modify it or connect to system without knowing the password by authorisation bypass. In this research-paper the proposed security model takes over all information inputted by user, adjusts the safety rules and that way it improves the safety in order to guard from SQL injections at electronic business web systems as well as it register potential attempts to disrupt normal work of the system. In order to install the proposed safety model there is no need to configure the server or its software because in the moment of installation it changes only files of website programs. For purpose of executing this work, we use PHP programming language and MySQL database. During the analysis, the received test results show what configuration parameters of safety model we need to use in order to guarantee the maximum level of safety.
Type Master thesis
Language Lithuanian
Publication date 2013