Advanced automated SQL injection attacks and defensive mechanisms
Vamshi Krishna Gudipati, Trinadh Venkata Swamy Naidu Venna, Soundarya Subburaj, Omar Abuzaghleh · 2016
SQL Injection vulnerabilities still exist even after almost two decades that it first appeared. In spite of numerous prevention methodologies being used today, web applications still tend to be vulnerable to SQL injection attacks. Technology has improved drastically over the past few years and computers have certainly brought a great impact on our lifestyle. The computer applications and their usage over the web are myriad. It is quite evident that the in the near future, the usage of computers would relatively be higher than what we are witnessing today. A wide variety of data such as credit information, military data, human communication data, and countless types of data is shared over the far-flung computer networks. As the usage and reliability on computers increase, the threat to sensitive data likewise increases. The challenges with the cyber security when dealing with sensitive information is now a nightmare. To help understand the threats and the severity of exploits deployed, the paper provides proof of concepts for exploits carried out to compromise web applications and how the databases are exploited using the SQL injection methodologies. The SQL injection vulnerabilities in the web applications are surprisingly very vast and this is definitely is a huge security threat to personal data of people that is stored on web. In this paper, the methods used in information gathering, how the security is breached, and how payloads are used to exploit web applications are explained using the Kali Linux. In addition, an analysis is carried out on how the websites are comprised. Advanced methods on how to defend SQL injections are briefly justified. For the readers to understand better, a real time scenario of a penetration tester and a database server is set up with a few suppositions, and the commands that dodge the security characteristics and manipulate the databases are explicated.