SQLIMW: A New Mechanism against SQL-injection
Jiao Gao, Changming Xu, Maohua Jing · 2012
SQL-Injection is an attack for Web applications which are based on database system, and it is one of the most serious security threats for Web application. This paper proposes a new middle-ware-based prevention mechanism: SQLIMW. The SQLIMW avoids SQL-Injection attack from the programmer to the server, and use HASH function to replace encryption. Furthermore, it protects username, password and private key of SQLIMW together by XOR operation and HASH. The proposal provides better security and efficiency.