首页> 外文会议>International Conference on Inventive Research in Computing Applications >WebApplication Vulnerabilities:Exploitation and Prevention
【24h】

WebApplication Vulnerabilities:Exploitation and Prevention

机译:Web应用程序漏洞:开发和预防

获取原文

摘要

Web application security has become a major challenge due to the common vulnerabilities found in web applications. Attackers possess a never-ending list of vulnerabilities and payloads to exploit them in order to gain access over various web applications maliciously. Each time when there are any changes made at some layer of web-application architecture, there exists a chance of creating novel vulnerabilities. In our work, the analysis is mainly focused on common and familiar vulnerabilities like Sql Injection (SQLi), Cross site Scripting (XSS) and Cross site Request Forgery (CSRF) and demonstrating the exploitation of these vulnerabilities by considering DVWA (Damn Vulnerable Web Application), a highly vulnerable web application designed for education purpose. The exploitation is carried out both manually and through automated tools. Thereby our research is concluded by inferring some preventive mechanisms to be adopted while designing the web applications to mitigate such types of attacks.
机译:由于Web应用程序中存在常见漏洞,因此Web应用程序安全性已成为一项主要挑战。攻击者拥有无穷无尽的漏洞和有效载荷列表,可以利用它们来恶意获取对各种Web应用程序的访问。每当在Web应用程序体系结构的某一层进行任何更改时,都存在创建新漏洞的机会。在我们的工作中,分析主要集中于常见和熟悉的漏洞,例如Sql Injection(SQLi),跨站点脚本(XSS)和跨站点请求伪造(CSRF),并通过考虑DVWA(该漏洞的Web应用程序)来演示这些漏洞的利用),这是一个为教育目的而设计的易受攻击的网络应用程序。该开发既可以手动执行,也可以通过自动化工具执行。因此,通过推断在设计Web应用程序以减轻此类攻击时应采用的一些预防机制,可以得出我们的研究结论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号