Automatic Protection of Web Applications Against SQL Injections: An Approach Based On Acunetix, Burp Suite and SQLMAP


연구 분야: Databases



학회: 2023 9th International Conference on Optimization and Applications (ICOA)


초록

Web application security is a critical concern in the digital world. One of the most common and dangerous vulnerabilities in web applications is SQL injection. SQL injection is an attack technique that allows a hacker to exploit security weaknesses in web applications that use SQL queries to interact with the database. This article presents a practical, step-by-step approach to detecting and exploiting the SQL injection vulnerability. The solution combined the use of Acunetix Web Vulnerability Scanner for detection, Burp Suite for capturing http requests containing parameters vulnerable to SQL injection, and SQLMAP as an automatic SQL Injection operating tool. The test was performed in a practical way using the real Damn Vulnerability Application and simulating SQL injection attack scenarios on each available security level: low, medium, and high. The results obtained showed very high performance of the solution at the different security levels, although the security mechanisms have been strengthened at these levels.


Author Profile
Rihab Bouafia

Engineering Sciences Laboratory National School of Applied Sciences Ibn Tofail University Kenitra Morocco

Morocco
Author Profile
Houssam Benbrahim

Engineering Sciences Laboratory National School of Applied Sciences Ibn Tofail University Kenitra Morocco

Morocco
Author Profile
Aouatif Amine

Engineering Sciences Laboratory National School of Applied Sciences Ibn Tofail University Kenitra Morocco

Morocco

📄 논문 정보

발행 연도 2023년
인용수 3
출판 국가 Morocco
사이트 IEEE
좋아요 수 0

연관 논문 목록 (320건)