Attack Analysis and Prevention of SQL Injection
He Yong
Abstract
He Yong
Abstract
SQL injection is a common loophole in Web system,the attacker can directly access database through the SQL statement,using this loophole,which caused seriously hidden trouble of safety.This paper analyzed the principle of SQL injection firstly,and then made exploration on SQL injection reasons and common ways of SQL injection attacks,finally,put forward the countermeasures to SQL injection attack,so as to provide guidance for SQL injection prevention in Web applications system.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
SQL injection is a common loophole in Web system,the attacker can directly access database through the SQL statement,using this loophole,which caused seriously hidden trouble of safety.This paper analyzed the principle of SQL injection firstly,and then made exploration on SQL injection reasons and common ways of SQL injection attacks,finally,put forward the countermeasures to SQL injection attack,so as to provide guidance for SQL injection prevention in Web applications system.
Key concepts: SQL injection, Autocommit, SQL/PSM, Computer science, SQL, Stored procedure, Data Transformation Services, Database