ZAŠTITA WEB APLIKACIJA OD SKRIPTNIH NAPADA (SQL INJEKTIRANJE, XSS NAPAD)
Barbara Strapač
Abstract
Barbara Strapač
Abstract
Due to the high use of online services and the provision of private information to enable services such as online shopping, online banking application services, healthcare application services and similar, the security of web applications and websites has become a key aspect of internet culture and application development. The aim of this final paper is to analyze security risks, testing methods and methods of protecting users' private information. In the first part of the final paper, we analyzed the methods of testing user input fields for SQL injection and Cross-Site Scripting attacks. In the second part we mentioned the programming languages, technologies and services we used in building the application, and in the last part we presented methods of protecting web applications from SQL injection and Cross-Site Script attacks on stored procedures, in PHP scripts and JavaScript scripts.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Due to the high use of online services and the provision of private information to enable services such as online shopping, online banking application services, healthcare application services and similar, the security of web applications and websites has become a key aspect of internet culture and application development. The aim of this final paper is to analyze security risks, testing methods and methods of protecting users' private information. In the first part of the final paper, we analyzed the methods of testing user input fields for SQL injection and Cross-Site Scripting attacks. In the second part we mentioned the programming languages, technologies and services we used in building the application, and in the last part we presented methods of protecting web applications from SQL injection and Cross-Site Script attacks on stored procedures, in PHP scripts and JavaScript scripts.
Key concepts: Cross-site scripting, Scripting language, JavaScript, SQL injection, World Wide Web, Computer science, Web application, Web application security