SQLIAD – A Hazard to Web Applications

Fyrooz Nidhal, Hiba Naser R N, Nahida Abdul Latheef, S. Shireen Siddique, Yomna Kalam A V, Neethu Prabhakaran P · International Journal of Computer Trends and Technology · 2015

SQLIA has been now a major threat to the growing popularity of web application. The main target of this attack is the database. This allows attackers to obtain unauthorised access to database .In this paper we survey different types of SQLIAs and prevention methods. To address this problem we propose a mixed approach for prevention of SQLIA .This paper ensures that the untrusted data are validated against a list of allowable values. Least privilege principle is applied to SQL account used by web application. We avoid query concatenation at almost all costs and use parameterized queries wherever possible.

Read the paper · More papers on PaperTik