A heuristic-based approach for detecting SQL-injection vulnerabilities in web applications

Angelo Ciampa, Corrado Aaron Visaggio, Massimiliano Di Penta · 2010

SQL injection is one amongst the most dangerous vulnerabilities for Web applications, and it is becoming a frequent cause of attacks as many systems are migrating towards the Web. This paper proposes an approach and a tool-named V1p3R ("viper") for Web application penetration testing. The approach is based on pattern matching of error messages and on outputs produced by the application under test, and relies upon an extensible knowledge base consisting in a large set of templates.

Read the paper · More papers on PaperTik