Information Systems Security (Paperback)

Langue : anglais

Edité par Springer-Verlag Berlin and Heidelberg GmbH & Co. KG, Berlin, 2010

3642177131 / 9783642177132

Vendeur : Grand Eagle Retail, Bensenville, IL, Etats-UnisGrand Eagle Retail

Vendeur avec une évaluation de 5 étoiles

Vendeur AbeBooks depuis 12 octobre 2005

Livre broché

Etat: Neuf

EUR 70,62

 Frais de port gratuits 
Expédition nationale : Etats-Unis

Quantité disponible : 1 disponible

Ajouter au panier
Retours gratuits sous 30 jours

A propos de cet article

Paperback. 2.1 Web Application Vulnerabilities Many web application vulnerabilities havebeenwell documented andthemi- gation methods havealso beenintroduced [1]. The most common cause ofthose vulnerabilities isthe insu?cient input validation. Any data originated from o- side of the program code, forexample input data provided by user through a web form, shouldalwaysbeconsidered malicious andmustbesanitized before use.SQLInjection, Remote code execution orCross-site Scriptingarethe very common vulnerabilities ofthattype [3]. Below isabrief introduction toSQL- jection vulnerability though the security testingmethodpresented in thispaper is not limited toit. SQLinjectionvulnerabilityallowsanattackertoillegallymanipulatedatabase byinjectingmalicious SQL codes into the values of input parameters of http requests sentto the victim web site. 1: Fig.1. An example of a program written in PHP which contains SQL Injection v- nerability Figure 1 showsaprogram that uses the database query function mysql query togetuserinformationcorrespondingtothe userspeci?edby the GETinput- rameterusername andthen printtheresultto the clientbrowser.Anormalhttp request with the input parameter username looks like "/ index.php?username=bob". The dynamically created database query at line2 is "SELECT * FROM users WHERE username='bob' AND usertype='user'". Thisprogram is vulnerabletoSQLInjection attacks because mysql query uses the input value of username without sanitizingmalicious codes. A malicious code can be a stringthatcontains SQL symbols ork- words.Ifan attacker sendarequest with SQL code ('alice'-') - jected "php?username=alice'-", the query becomes "SELECT* FROM users WHERE username='alice'--' AND usertype='user'". Constitutes the refereed proceedings of the 6th International Conference on Information Systems Security, ICISS 2010, held in Gandhinagar, India, in December 2010. Shipping may be from multiple locations in the US or from the UK, depending on stock availability.…

N° de réf. du vendeur 9783642177132

Titre
Information Systems Security (Paperback)
Auteur
Somesh Jha
Éditeur
Springer-Verlag Berlin and Heidelberg GmbH & Co. KG, Berlin
Année de publication
2010
État de l'article
new
Reliure
Paperback
Langue
anglais
ISBN à 10 chiffres
3642177131
ISBN à 13 chiffres
9783642177132

Grand Eagle Retail

Bensenville, IL, Etats-Unis

Vendeur avec une évaluation de 5 étoiles

Vendeur AbeBooks depuis 12 octobre 2005

Frais d'expédition à l'intérieur de ce pays : Etats-Unis

Article6 à 14 jours ouvrés6 à 16 jours ouvrés
Premier articleEUR 0,00EUR 0,00
Les délais de livraison sont fixés par les vendeurs et varient en fonction du transporteur et du lieu. Les commandes transitant par les douanes peuvent être retardées et les acheteurs sont responsables de tous les droits ou frais associés. Les vendeurs peuvent vous contacter au sujet de frais supplémentaires afin de couvrir toute augmentation des coûts d'expédition de vos articles.

Modes de paiement

  • Visa
  • Mastercard
  • American Express
  • Carte Bleue
  • Apple Pay
  • Google Pay

Profil professionnel du vendeur

APOLLO ONLINE CORP.

605 Geddes Street
Wilmington, DE Etats-Unis 19805