Detection and Prevention of Data Manipulation from Client Side in Web Applications
Mohammad Hossein Ghafari, Hamid Shoja, Mohammad Yosef Amirani · 2012
One of the most critical attacks against web applications is data manipulation classified in logical attacks. They are not identified by automated vulnerability scanners, so they need human surveillance in many cases. This paper provides a server-side validation mechanism which leverages from user's access level to prevent a kind of manipulation of data exchanged between client and server and guarantees originality of data. This manipulation executes in order to modify vital parameters' value in a way, in which user often shouldn't be able to. The results of case study show the feasibility and applicability of the proposed method in almost all cases. Furthermore, it can be applied in ready applications with few changes in target application.