e-ISSN : 0975-4024 p-ISSN : 2319-8613   
CODEN : IJETIY    

International Journal of Engineering and Technology

Home
IJET Topics
Call for Papers 2021
Author Guidelines
Special Issue
Current Issue
Articles in Press
Archives
Editorial Board
Reviewer List
Publication Ethics and Malpractice statement
Authors Publication Ethics
Policy of screening for plagiarism
Open Access Statement
Terms and Conditions
Contact Us

ABSTRACT

ISSN: 0975-4024

Title : Detection and Avoidance of SQL Injection Attack In Multi-Tier Web Based Application
Authors : Ms. S.Raichal, Ms.Soniya, Ms. V.M.Gayathri, Dr. R.Nedunchelian
Keywords : SQL injection, stored procedure, conditional statement.
Issue Date : Jun-Jul 2013
Abstract :
The aim of this paper is to prevent sql injection attack using stored procedure. In SQL injection attack, an attacker might deliver malicious SQL query segments as user input which could effect in a different database request. Using SQL injection attacks, an attacker might thus obtain and modify confidential information. An attacker could even use a SQL injection vulnerability as a basic IP or Port scanner of the internal corporate network. The stored procedure does not permit conditional statement there by the hacker cannot identify the IDs. The stored procedure is the new approach that is executed. Stored procedure avoids the attack which is more secured one where the conditional statements are not permitted. In sql injection input is set as conditional statements and the user can able to login into the website. But in this paper every condition are checked in the procedural language of stored procedure. Once it notices the condition statement the user will be blocked to log into the website. Only the correct form of passwords is acceptable.
Page(s) : 2842-2847
ISSN : 0975-4024
Source : Vol. 5, No.3