首页> 美国卫生研究院文献>The Scientific World Journal >Vulnerability Assessment of IPv6 Websites to SQL Injection and Other Application Level Attacks
【2h】

Vulnerability Assessment of IPv6 Websites to SQL Injection and Other Application Level Attacks

机译:IPv6网站对SQL注入和其他应用程序级别攻击的漏洞评估

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Given the proliferation of internet connected devices, IPv6 has been proposed to replace IPv4. Aside from providing a larger address space which can be assigned to internet enabled devices, it has been suggested that the IPv6 protocol offers increased security due to the fact that with the large number of addresses available, standard IP scanning attacks will no longer become feasible. However, given the interest in attacking organizations rather than individual devices, most initial points of entry onto an organization's network and their attendant devices are visible and reachable through web crawling techniques, and, therefore, attacks on the visible application layer may offer ways to compromise the overall network. In this evaluation, we provide a straightforward implementation of a web crawler in conjunction with a benign black box penetration testing system and analyze the ease at which SQL injection attacks can be carried out.
机译:鉴于互联网连接设备的激增,已经提出了IPv6替代IPv4的建议。除了提供可以分配给启用Internet的设备的更大地址空间外,由于存在大量可用地址,标准IP扫描攻击将不再可行,因此有人建议IPv6协议提供更高的安全性。但是,由于有兴趣攻击组织而不是单个设备,因此可以通过Web爬网技术看到并访问组织网络及其附带设备的大多数初始入口点,因此,对可见应用程序层的攻击可能会提供破坏途径整个网络。在此评估中,我们结合良性黑匣子渗透测试系统提供了Web爬网程序的直接实现,并分析了执行SQL注入攻击的难易程度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号