首页> 外文会议>2015 Second International Conference on Information Security and Cyber Forensics >SQLi vulnerabilty in education sector websites of Bangladesh
【24h】

SQLi vulnerabilty in education sector websites of Bangladesh

机译:孟加拉国教育部门网站中的SQLi漏洞

获取原文
获取原文并翻译 | 示例

摘要

Bangladesh has announced every Government & Non -Government school and colleges must website. The Web sites have to include all data and information every school and colleges. The goal of this initiative is to ensure equal quality of education and to provide education to the remote areas of the country. Though is a very new concept yet an appreciable number of institutes have already started shifting their systems online. While this advancement is commendable yet there are drawbacks such as security risks of these Web sites and the data in them. One of the easiest yet treacherous security risks of website is SQLi. This paper focuses on various types of SQLi vulnerabilities such as: normal, error based double query, and blind injection techniques and their aggression on the educational Web sites of Bangladesh. Manual penetration testing with black box approach has been implemented in number of Web applications to check the vulnerabilities. The data found has been analyzed to draw statistical conclusion of the present condition of the educational Web sites of Bangladesh.
机译:孟加拉国已经宣布了每所政府和非政府学校和大学都必须访问的网站。网站必须包含每个学校和学院的所有数据和信息。该计划的目标是确保教育质量平等,并向该国偏远地区提供教育。尽管这是一个非常新的概念,但是已经有相当数量的机构开始在线转移其系统。尽管这种进步值得称赞,但存在诸如这些网站及其中数据的安全风险之类的缺点。 SQLi是网站最简单但最危险的安全风险之一。本文重点介绍各种类型的SQLi漏洞,例如:正常,基于错误的双重查询和盲注技术及其在孟加拉国教育网站上的攻击性。已经在许多Web应用程序中实施了带有黑盒方法的手动渗透测试,以检查漏洞。分析发现的数据以得出孟加拉国教育网站现状的统计结论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号