0% found this document useful (0 votes)
15 views3 pages

2 SQLinjection Nov 2014

The paper discusses SQL Injection Attacks (SQLIAs) as a significant security threat to web applications and databases, highlighting the ease of access to automated tools for attackers. It illustrates various attack patterns and emphasizes the need for dynamic security protocols to mitigate these vulnerabilities. The authors also provide a live example of an SQL injection attack on an educational website, demonstrating the potential risks and impacts of such attacks.

Uploaded by

ahmad12345000001
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views3 pages

2 SQLinjection Nov 2014

The paper discusses SQL Injection Attacks (SQLIAs) as a significant security threat to web applications and databases, highlighting the ease of access to automated tools for attackers. It illustrates various attack patterns and emphasizes the need for dynamic security protocols to mitigate these vulnerabilities. The authors also provide a live example of an SQL injection attack on an educational website, demonstrating the potential risks and impacts of such attacks.

Uploaded by

ahmad12345000001
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

International Journal of Advanced Networking Applications (IJANA) ISSN No.

: 0975-0290 91

Live Experiments depicting SQL Injection


Attacks
Prof. Disha H. Parekh
Research Scholar, Bharathiar University,
Coimbatore, India.
disha.hparekh213@[Link]
Mr. Dhaivat Dave
MCA – 3rd Semester, Faculty of Computer Applications, Marwadi Education Foundation’s Group of Institutions
Rajkot, Gujarat, India.
Email: davedhaivat@[Link]
Dr. R. Sridaran
Dean, Faculty of Computer Applications, Marwadi Education Foundation’s Group of Institutions
Rajkot, Gujarat, India.
Email: [Link]@[Link]
----------------------------------------------------------------------ABSTRACT-------------------------------------------------------------
Abstract— The paper explores one of the major security issue of existing and forthcoming deployment of cloud and
other web technologies, the SQL Injection Attacks (SQLIAs). The existing attackers who may range from a novice
student who wants to research on security to a seasoned hacker, have it easy due to the presence and easy availability
of SQLIAs automated tools. It should also be noted that the attack pattern might vary from person to person leading
to absence of a perfect countermeasure for the same. The paper also illustrates an example attack pattern explaining
a possible chain of sequence in which attack can occur.
Keywords - SQL Injection Attacks, Havij, web vulnerabilities

of attacks. Besides this, the enormous majority of these


I. INTRODUCTION solutions are based on centralized mechanisms showing
very little capacity to work in dynamic and distributed
environments.

P resently, one of the most dodgy and attention seeking


problem with web applications and database is SQL
Injection Attacks. These attacks are very commonly
known as SQLIAs, where inside the SQL query certain
SQL Injection Attacks are dealt as a massive threat because
it injects into the web applications and accesses a database
underlying the web. This data can be highly confidential
and can be of a very high value like bank transactions or list
clause is maliciously modified or is added without any
proper authorization. These leads to various hazardous of financial transactions that may incur a lot of secret
situations where the queries will break into the system and information. An unauthorized access to such important
because they are modified will result into generation of an database by a crafted user can result in the threat to CIA i.e.
output as intended by the attacker. Such problems and Confidentiality, Integrity and Authority of the database.
malicious attacks are being frequently observed in day to Such malicious attacks may result in giving proper services
day life. It will not only modify the database, but will also to their users and as a consequence, a company or bank’s
serve an illegal or an unauthorized person to access it and existence may be threatened. Hence, according to Diallo
use it without authenticity. Abdoulaye Kindy et. al. [3] SQL Injection could be very
unsafe in many cases depending on the platform where the
SQLIAs have been found as the top priority problem that attack is commenced and it gets triumph in injecting rogue
exists with current network issues. According to D.H. users to the target system.
Parekh et. al. [1], various cloud computing challenges are
identified under which networking issues discuss about II. RELATED WORK
SQLIAs as a malicious act on the cloud computing in which In the paper by Jaskanwal Minhas et. al. [4] have focused
a spiteful code is inserted into a model SQL code allowing on attribute removals from queries, static and Dynamic,
the invader to access database and eventually to other both, and compared them. The method proposed minimizes
confidential information in an unauthorized manner. the response time by character wise comparison of
Though being so very prominent type of attack, the SQL incoming queries with static queries with same number of
injection still is at the top of the list of security threats [2]. tokens. The authors were yet to work on detection and
The solutions identified so far seem insufficient to avoid prevention of several other attack modes like cross site
and block this type of attack because certain solutions is scripting attacks.
devoid of the learning and adaptation abilities for dealing Erwin Adi [5], in his paper, proposes a method to blacklist
with previously unseen attacks as well as future distinctions codes and strings that are malicious and use this database
International Journal of Advanced Networking Applications (IJANA) ISSN No. : 0975-0290 92

block the attacks. The author proposes the work further to


neutralize such attacks rather than blocking them. In order
to do any of these, the author concludes that the input size
has to be made limited. This can be achieved in one out of
many ways by implementing an interface between query
generation and database.
In the paper by L. K. Shar et. al. [6], the two phased
approach to detect and block the malicious statements has
been discussed that uses taint based analysis approach and
later the pattern making and data dependency analysis is
generated on the basis of the same. They have generated an
equivalent replacement code to reduce the possibility of
SQL injection. But in the paper they have not shown any
analysis technique that tracks the flow of user inputs to
accurately detect its influence in HTML output statements.
Any site designed or hosting important data or precious
III. SQL INJECTION RISKS content incorporate to be an easy target. Age is also a rough
Even though SQL injection has been identified as the most indicator of vulnerability to security risks. Similar indicator
dangerous issue for years, there are numerous factors that is the number of servers hosting the site and number of
augment the rate of risk. Initially, more companies offer maintenance or access points. This makes the third party
website interaction with visitors and this drift is increasing security risk review important as well as necessary.
radically. Secondly, more hackers gain skills in SQL Improper and non timely updates can also become an
injection which helps them in discovering more applications important and vicious vulnerability [9].
and services that are prone to attack and are mounting new
attacks on old applications. This results in an exponential IV. SQL INJECTION EXAMPLE
increase in the opportunities to use this attack method [7]. In order to reveal SQLIA’s, a particular education website
Risk of being attacked using SQL injection is based on two was targeted. After performing several tests, it was found
factors: the nature and size of your business and the age, that the site is susceptible to SQL Injection Attacks. A step
status of updates and patches on your applications and the by step approach was followed to reach till the database and
skill and number of your technical staff. It boils down to find the admin username and password. Moreover, Havij
whether you are an interesting target and whether your web which is an automated SQL Injection tool was used to find
server, the applications on it and your web site code are and exploit vulnerabilities of the website [10]. Through the
well designed, well integrated and have all the current tool we were able to detect the username and the password
patches and updates. of the admin. Following queries reveal the steps of how a
chain of SQL Injection attacks were used to successfully
The site faces critical danger if it is used to host data of high
infiltrate given site. Through this it is exemplified how
significance, if business or applications are in high demand
different focused attack patterns may exploit a series of
and dense competition, or if it has socio-political impact.
distinct minor vulnerabilities to construct a major attack.
The target also becomes obvious choice if it deals with
money. Websites for blogs and other social media become 1. ***.[Link]/[Link]?p=mba&id=2'
an important target when they are pioneer in the This query was fired to state that the website was
information that is of great impact. vulnerable to SQL Injection Attacks. The name of the
SQL injection attacks are easily implemented or outsourced targeted domain is not mentioned intentionally for the sake
online. An upset consumer, a rival, or any acquaintance can of confidentiality.
have an easy access to something commonly known as a 2. ***.[Link]/[Link]?id=1+/*!UnIoN*/+/*!sELe
'script kiddie' - and in worst case, a talented hacker - to Ct*/1,2,3,4,5,6,7--
attack a site. The probability of the attacker getting caught
is very low. It is very easily possible that the attacker might Query resulted an integer value on the screen which showed
not be noticed even after much damage has been already that number 3 was susceptible to attacks.
done [8]. Figure 1, depicts that how an SQL Injection 3. ***.[Link]/[Link]?id=1+/*!UnIoN*/+/*!sELe
Attacks are targeted on the domain. Moreover, it also shows Ct*/1,2,database(),4,5,6,7--
how the user accesses various servers through the
With this query database of the site was fetched.
vulnerabilities at each stage.
4. ***.[Link]/[Link]?id=1+/*!UnIoN*/+/*!sELe
Ct*/1,2,version(),4,5,6,7--
This query showed the version of the SQL, and if it is
above 5.0.0, it ensures that our SQL Attacks would work.
International Journal of Advanced Networking Applications (IJANA) ISSN No. : 0975-0290 93

5. ***.[Link]/[Link]?id=1+/*!UnIoN*/+/*!sELe [7] Priyadarshini, R.; Jagadiswaree, D.; Fareedha, A.;


Ct*/1,2,table_name,4,5,6,7 from Janarthanan, M. "A cross platform intrusion detection
information_schema.tables--
system using inter server communication technique",
When the above query was fired, it gave the names of all Recent Trends in Information Technology (ICRTIT),
the tables that were there in the database. 2011 International Conference on, pp. no: 1259 - 1264
[8] M. Vieira, N. Antunes, and H. Madeira, “Using Web
6. ***.[Link]/[Link]?id=1+/*!UnIoN*/+/*!sELe
Ct*/1,2,group_concat(column_name),4,5,6,7 from Security Scanners to Detect Vulnerabilities in Web
information_schema.columns where table_name Services,” Proc. 39th Ann. IEEE/IFIP Int'l. Conf.
=CHAR (109,101,100,109,97,105,110)-- Dependable Systems and Networks (DSN 09), IEEE,
2009, pp. no: 566-571.
With this query, the id and password of the admin table was
[9] Sadeghian, A.; Zamani, M.; Abdullah, S.M. "A
fetched.
Taxonomy of SQL Injection Attacks", Informatics
When the above examples were tested with Havij, the and Creative Multimedia (ICICM), 2013 International
results were almost same. Tables, username and password, Conference on, pp. no: 269 – 273.
database and column names, reported by Havij were the [10] A. Kebert, B. Banerjee, G. George, J. Solano, and W.
same as those given by the above queries. Solano. Detecting Distributed SQL injection attacks in
a Eucalyptus Cloud environment. In Proceedings of
[Link] the 12th International Conference on Security and
As we observe the attack pattern can exploit existing Management (SAM-13), CSREA Press, Las Vegas,
NV, July 2013.
vulnerabilities at several different levels to generate a major
AUTHORS PROFILE
attack. Availability of automated tools aiding SQLIAs ease
I. Ms. Disha H. Parekh, MCA, PGDBA (Human
the work for attackers. Depending on the experience,
Resource), is presently an Assistant Professor of
attackers might breach some or all of the security measures. Faculty of Computer Applications at Marwadi
The security protocols of the deployed project should be Education Foundation’s Group of Institutions, Rajkot,
made as dynamic as possible to avoid SQLIAs and yet with Gujarat. She has done MCA from Ganpat University,
more stealth to protect it continuously while providing Gujarat. She has completed PGDBA. with
seamless access to the data. specialization in HR from Symbiosis University. She
References has published 3 papers in the International Journal and
[1] Disha H. Parekh, Dr. R. Sridaran, “An Analysis of has presented 1 paper at National conference. She has
Security Challenges in Cloud Computing”, attended many workshops and Seminars. Her areas of
International Journal of Advanced Computer Science interest are Software Engineering and Web
and Applications, Vol. 4, No. 1, 2013, pp. no: 38 – 46, Technologies. She is currently pursuing Ph.D in
January, 2013 Bharathiyar University.
[2] W.G.J. Halfond, J. Viegas, A. Orso, “A classification II. Mr. Dhaivat Dave is a student of Marwadi
of SQL-injection attacks and countermeasures”, IEEE College, studying in MCA Semester 3. He has
International Symposium on Secure Software completed his BCA from Vivekananda College
Engineering, Arlington, VA, USA, 2006. (Bhavnagar University). He has done a certified
[3] Diallo Abdoulaye Kindy and Al-Sakib Khan Pathan, course of Cyber Security Expert v2.0 from
“A Survey on sql injection: vulnerabilities, attacks, TechDefence Ahmedabad. His area of interest falls
and prevention techniques”, IEEE 15th International under the field of security related issues on network.
Symposium, June 2011, pp. no: 468 – 471. III. Dr. R. Sridaran has done his post graduation in
[4] Jaskanwal Minhas and Raman Kumar “Blocking of Computer Applications and Management. He has been
SQL Injection Attacks by Comparing Static and awarded the Ph.D in Computer Applications in 2010.
Dynamic Queries”, I. J. Computer Network and Having started his career as an Entrepreneur, he has
Information Security, 2013, 2, 1-9 Published Online offered his consultancy services to various service
February 2013 in MECS, DOI: sectors. He has also designed and delivered various
10.5815/ijcnis.2013.02.01 training programs in the areas of IT & Management.
[5] Erwin Adi, “A design of a proxy inspired from human He has published 14 research papers in leading
immune system to detect SQL Injection and Cross-Site Journals and Conferences and presently guiding four
Scripting”, International Conference on Advances research scholars. He has got 19 years of academic
Science and Contemporary Engineering 2012 experience and served in leading educational
(ICASCE 2012) institutions at different capacities. He is currently the
[6] Lwin Khin Shar, Hee Beng Kuan Tan “Automated Dean, Faculty of Computer Applications, Marwadi
removal of cross site scripting vulnerabilities in web Education Foundation’s Group of Institutions, Rajkot,
applications”, Information and Software Technology, Gujarat.
IEEE, 54, 2012 [Link]–478.

You might also like