Determining sql injection vulnerabilities through payload
2022
0 views
0 downloads
Advisor: Prof. Dr. Resul Kara
Abstract (EN)
Along with the constantly developing technology, the use of computer systems is increasing in parallel with the needs such as rapid access to information, storage. In these systems, especially institutions and organizations hold and use important information. As in every field, computer systems are under threat by cyber attackers because of the important resources they have. As in all areas, security measures are taken against these threats. Hardware and software precautions such as firewalls, intrusion detection and prevention systems (IPS/IDS), content filtering systems, anti virus software, code security tightening are taken. Various cyber attacks are carried out by cyber attackers in order to seize especially critical and confidential information on computer systems. One of these cyber attacks is the Structured Query Language (SQL) injection attack, which is the most common and most dangerous type of attack. A SQL injection attack is a form of exploitation of a security vulnerability by exploiting the vulnerabilities of the codes on the application using a database, with the aim of obtaining confidential information without the authorization of the cyber attacker. In this thesis, SQL injection, classification of SQL injection attacks, methods of detecting SQL injection vulnerability are explained. Studies have been carried out to determine SQL injection vulnerability on web applications. These studies were carried out on Damn Vulnerable Web Application (DVWA) and Web For Pentester applications, which were created for web application security and contain web security vulnerabilities. Manual queries and web vulnerability and penetration testing tools such as Burp Suite, Sqlmap, Kali Linux, Havij, Acunetix, Netsparker were used to identify SQL injection vulnerability. The data loads performed by these tools and manual SQL injection queries were analyzed and compared.
Author
Ramazan Cankuş
Institution
How to Cite
Ramazan Cankuş (Master Thesis). Determining sql injection vulnerabilities through payload, 2022, Düzce University.
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Düzce University
- A review of Cem Akaş's novels(2021)
- New midpoint type inequalities for generalized fractional integrals(2021)
- Material culture in Mostarli Hasan Ziya'i Divan(2021)
- The life of Ebu'l-Hasen Ali b. Ahmed b. Muhammed en-Nîsâbûrî el-Vâhidî and his method in the tafsir named el-Vecîz fî Tefsîr-i Kitabi'l-Azîz(2021)
- Intertextuality in Alev Alatlı's novel's(2022)
- Visual interpretations on dark humor(2022)
