Title :
Analysis of SQL injection attack in web service (a case study of website in Aceh province)
Author :
Munadi, Rendy ; Surya Fajri, T. ; Meutia, Ernita Dewi ; Mustafa, Elizar
Author_Institution :
Lab. Jaringan Komput., Univ. Syiah Kuala, Banda Aceh, Indonesia
Abstract :
Dissemination of information through the Internet is one of the positive impacts of the ICT technology and an efficient way to reach everyone around the world. Everyone will easily access all of the information presented by the restrictions place unhindered. Therefore, various government agencies, private organizations, educational institutions, and other nonprofit organizations in Aceh are using the Internet as a medium for information dissemination. Development of the site becomes easier with the availability of applications Content Management System (CMS), which is combined with the PHP scripting language and MySQL database. However, various security issues can harm the existence of Web site system and it seems not to be the attention of the administrator and Web master. Security issues were examined in this study based on a variety of attacks that occur by the method of SQL injection attacks. A survey of existing sites in the province of Aceh has been carried out and found the data were obtained and then were classified into the attack happened. Based on the result of this study, some preventive measures were established that need to be understood and implemented so that SQL injection can be minimized in the future.
Keywords :
SQL; Web services; Web sites; authoring languages; content management; information dissemination; pattern classification; security of data; Aceh province; CMS; ICT technology; MySQL database; PHP scripting language; SQL injection attack analysis; Web service; Web site system; content management system; data classification; information dissemination; security issues; Educational institutions; Government; Information technology; Internet; Security; Testing; Attack; Information; SQL Injection; Security; Website;
Conference_Titel :
Instrumentation, Communications, Information Technology, and Biomedical Engineering (ICICI-BME), 2013 3rd International Conference on
Conference_Location :
Bandung
Print_ISBN :
978-1-4799-1649-8
DOI :
10.1109/ICICI-BME.2013.6698541