期刊文献+

基于Web服务的数据库注入攻击与防范 被引量:5

Database Injection Attack and Defense Based on Web Server
下载PDF
导出
摘要 介绍了SQL注入攻击的发生原理和完全控制服务器的快捷方法及对Web服务器带来极大的危害,给出了相应的SQL执行脚本和对应的防范攻击措施,以供开发Web程序和架设服务器时参考. The occurrence principles of the attack about SQL pouring into Web server are introduced,the quick method of contolling the server completely is described,thus the bringing enormous harms for the Web server are also described,corresponding SQL to carry out the script is given,the corresponding measures to guard against this kind of attack are also given. It is a reference for developing the Web procedure as well as erecting the server.
作者 郜激扬
出处 《华北水利水电学院学报》 2008年第1期89-91,共3页 North China Institute of Water Conservancy and Hydroelectric Power
关键词 SQL注入 Web漏洞 数据库攻击 安全防范 SQL injection Web leak database attack safety defense
  • 相关文献

参考文献6

二级参考文献15

  • 1Cesar Cerrudo.Manipulating microsoft SQL ser-ver using SQL injecti on.[EB/OL].http://www.appsecinc.com/presentations/Manipulat- ing_SQL_Server _using _SQL_Injection.pdf.2004-3-25.
  • 2SPI LABS.SQL Injection[EB/OL]. http://www.spidynamics.com/pa pers/SQL Injection WhitePaper.pdf.2004-3-25.
  • 3ANSI.DIS 90751992,Information technology - Database language SQL[S] .
  • 4ISO/IEC.ISO/IEC 9075:1992.Information technology - Database language SQL[S].
  • 5ISO/IEC.ISO/IEC 9075-5:1999.Information technology - Database language SQL[S].
  • 6WebCohort.WebCohort;s application defense center reports results of vulnerabil ity testing on Web applications.[EB/OL].http://www.imperva.com/com pany/news/2004-feb-02.html.2004-3-25.
  • 7Stephen Kost.An Introduction to SQL injection attacks for Oracle developers.[EB/OL].http://www.integrigy.com/papers.htm.200 4-3-25.
  • 8Chris Anley.Advanced SQL injection in SQL server applications.[EB/OL].http://www.nextgenss.com/research.html,2004-3-25.
  • 9Ofer Maor,Amichai Shulman.Blindfolded SQL injection.[EB/OL].http://www.im perva.com/application_defense_center/white_papers/blind_sql_s erver_injection.html.2004-3-25.
  • 10Chris Anley.More advanced SQL injection.[EB/OL]. http://www. nextgenss.com/papers/more_advanced_sql_injection.pdf.2004-3-25.

共引文献84

同被引文献26

引证文献5

二级引证文献18

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部