files/journal/2022-09-02_11-59-20-000000_418.png

Asian Journal of Information Technology

ISSN: Online 1993-5994
ISSN: Print 1682-3915
96
Views
1
Downloads

Automatic Prevention of Union Query Type SQL Injection Attack Using Private Synonym and Error Message Controller

N. Gunaseeli and D. Jeya Mala
Page: 4445-4449 | Received 21 Sep 2022, Published online: 21 Sep 2022

Full Text Reference XML File PDF File

Abstract

Web applications are software applications which allow the end users to access the most valuable services like credit card services, purchase orders, online booking services and so on. The developers of the web applications pay more concentration on developing the features and functionality of the applications. They spend only little amount of time to secure web applications. Unfortunately, the web applications are vulnerable to various threats like SQLIA, cross site scripting, buffer overflow, etc. Despite, the web applications are vulnerable to many kinds of threats and attacks, SQLIA (SQL injection attack) is the most vulnerable to web applications. It is a kind of attack where malicious users try to access the database layer of an application through crafted input query strings. Ignoring the existence of these kinds of attacks leads to various kinds of SQLIA. One among them is union queries SQL injection attack. Through this attack, an attacker gets the result set of original query along with the result set of injected query. This study analyzes the weaknesses of union query SQL injection attack and proposes a novel approach to prevent the union query at run time.


How to cite this article:

N. Gunaseeli and D. Jeya Mala. Automatic Prevention of Union Query Type SQL Injection Attack Using Private Synonym and Error Message Controller.
DOI: https://doi.org/10.36478/ajit.2016.4445.4449
URL: https://www.makhillpublications.co/view-article/1682-3915/ajit.2016.4445.4449