首页> 外文会议>ICCSE 2012;International Conference on computer science & education >A prototype system to scrutinize PHP code injection attacks
【24h】

A prototype system to scrutinize PHP code injection attacks

机译:审查PHP代码注入攻击的原型系统

获取原文

摘要

The growth of web applications on Internet has led to the increase in cyber crime. The attacker may inject malicious code into text boxes of vulnerable web application such as guest book, feedback form, search box, etc. which may be further executed by web server. The execution of system call and API on web server by attacker through PHP code injection may damage the file system or leaks configuration information of web server. PHP code injection attacks have become more extensive in nature due to the emergence of dynamic web paradigms. Dynamic features and functionalities of a web site are controlled through PHP language. Hence, the use of PHP language (which itself carries vulnerabilities) in dynamic web page results in higher possibilities of successful execution of code injection attacks. The aim of this paper is twofold. Firstly, to understand the web application vulnerabilities related to PHP code injection attack, two PHP code injection attack scenarios have been developed. Secondly, to accurate and fast incident determination from gathered evidences a tagging system based on domain dictionary has been developed. The proposed prototype system shall be helpful for law enforcement agency to effectively gather and analyze evidences subjected to PHP code injection attacks.
机译:Internet上Web应用程序的增长导致网络犯罪的增加。攻击者可能将恶意代码注入易受攻击的Web应用程序的文本框中,例如,留言簿,反馈表单,搜索框等,这些文本框可能会进一步由Web服务器执行。攻击者通过PHP代码注入在Web服务器上执行系统调用和API可能会损坏文件系统或泄漏Web服务器的配置信息。由于动态Web范例的出现,PHP代码注入攻击的性质已经变得更加广泛。网站的动态功能是通过PHP语言控制的。因此,在动态网页中使用PHP语言(本身带有漏洞)会导致成功执行代码注入攻击的可能性更高。本文的目的是双重的。首先,为了了解与PHP代码注入攻击相关的Web应用程序漏洞,已经开发了两种PHP代码注入攻击方案。其次,为了从收集到的证据中准确快速地确定事件,开发了基于域字典的标记系统。所提出的原型系统将有助于执法机构有效地收集和分析遭受PHP代码注入攻击的证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号