Logo Lanfrica
  • Accueil
  • Atlas
  • Analyses
  • Documentation
  • Sign in

© 2026 Lanfrica. Tous droits réservés. Tous les droits d'auteur des ressources affichées sur le site Web Lanfrica appartiennent aux détenteurs de droits d'auteur d'origine, sauf indication contraire explicite.

A Study of Online Database Servers: The Case of SQL - Injection, How Evil that could be?

Domaine:

digital infrastructure

Type de record:

paper
Créateur:
S.
Éditeur:
Dep
Éditeur:
CCSD
Hôte:avatar
International audience SQL injection attack is one of the most serious security vulnerabilities in many Databases Managements systems. Most of these vulnerabilities are caused by lack of input validation and SQL parameters used particularity at this time of technology revolution. The results of a SQL injection attack (SQLIA) are unpleasant because the attacker could wipe the entire contents of the victim's database or shut it down. As such, SQLIA can be used as important weapons in cyber warfare. As an attempt of breaching of number of application data bases systems two SQL injection techniques were used to successful locating vulnerable points during this research which are Blind Text Injection Differential and Error based Exploitation. The motivations behind were to find out where the databases systems are most likely to face an attack and proactively shore up those weaknesses before exploitation by hackers. The success of both techniques is a result of poor web server (online database server) design especially in the selection of error messages (or answers) they display to website users if something goes wrong. The approach through examination of error messages (error codes) did enable to precisely know the backend Database Management System (DBMS) type and version and what exactly are parameters (variables) which can allow “illegally” injecting codes (a SQL query). Additionally, the paper presents SQLIA cases and their impact in Tanzania cyber space as well as it suggests the possible mitigation ways while reflecting the collected data with what currently existing in cyberworld as far as SQL injection attack is concern to present the reality.

Visit

hal.science

Tags

[INFO]Computer Science [cs]

Similaires

An Evil to be Extinguished or a Resource to be harnessed-Informal Sector in Developing Countries: A Case of ZimbabweIntroducing a New Lexicographical Model: AlphaConceptual+ (and How it Could Be Applied to Dictionaries for Luganda)“TO BE OR NOT TO BE, THAT IS THE QUESTION”: THE CASE OF LITHOKO VS PRAISE POETRY.How Could Something So Right Be So Wrong? OT References to the Left and Right HandThe Evil Couple: Illegal Mining in Water Bodies and Climate Change: A Case Study of GhanaCOULD DIGITAL UBUNTU BE THE SOUTH AFRICAN VERSION OF INDUSTRY 4.0?

An Evil to be Extinguished or a Resource to be harnessed-Informal Sector in Developing Countries: A Case of Zimbabwe

The informal sector remains a permanent feature of all economies. It is a more pronounced component

Introducing a New Lexicographical Model: AlphaConceptual+ (and How it Could Be Applied to Dictionaries for Luganda)

“TO BE OR NOT TO BE, THAT IS THE QUESTION”: THE CASE OF LITHOKO VS PRAISE POETRY.

For a long time, lithoko have been understood and so referred to as not just poetry but praise poetr

How Could Something So Right Be So Wrong? OT References to the Left and Right Hand

Cross-culturally the left hand is considered the lesser member of the right-left pair, giving rise t

The Evil Couple: Illegal Mining in Water Bodies and Climate Change: A Case Study of Ghana

For the past few decades, illegal mining sector in Ghana popularly known as galamsey has received pu

COULD DIGITAL UBUNTU BE THE SOUTH AFRICAN VERSION OF INDUSTRY 4.0?

Advanced technologies are satisfying the demands of individuals and of industry. But what about empl