Information Systems Security (Paperback)

Idioma: inglés

Editorial: Springer-Verlag Berlin and Heidelberg GmbH & Co. KG, Berlin, 2010

3642177131 / 9783642177132

  • Tapa blanda
  • Nuevo
Ver todos los detalles

Librería: Grand Eagle Retail, Bensenville, IL, Estados Unidos de AmericaGrand Eagle Retail

Vendedor de 5 estrellas

Vendedor de IberLibro desde 12 de octubre de 2005

Tapa blanda

Condición: Nuevo

EUR 70,54

 Gastos de envío gratis 
Se envía dentro de Estados Unidos de America

Cantidad disponible: 1 disponible

Añadir al carrito
Devoluciones gratuitas de 30 días

Descripción del artículo del vendedor

Paperback. 2.1 Web Application Vulnerabilities Many web application vulnerabilities havebeenwell documented andthemi- gation methods havealso beenintroduced [1]. The most common cause ofthose vulnerabilities isthe insu?cient input validation. Any data originated from o- side of the program code, forexample input data provided by user through a web form, shouldalwaysbeconsidered malicious andmustbesanitized before use.SQLInjection, Remote code execution orCross-site Scriptingarethe very common vulnerabilities ofthattype [3]. Below isabrief introduction toSQL- jection vulnerability though the security testingmethodpresented in thispaper is not limited toit. SQLinjectionvulnerabilityallowsanattackertoillegallymanipulatedatabase byinjectingmalicious SQL codes into the values of input parameters of http requests sentto the victim web site. 1: Fig.1. An example of a program written in PHP which contains SQL Injection v- nerability Figure 1 showsaprogram that uses the database query function mysql query togetuserinformationcorrespondingtothe userspeci?edby the GETinput- rameterusername andthen printtheresultto the clientbrowser.Anormalhttp request with the input parameter username looks like "/ index.php?username=bob". The dynamically created database query at line2 is "SELECT * FROM users WHERE username='bob' AND usertype='user'". Thisprogram is vulnerabletoSQLInjection attacks because mysql query uses the input value of username without sanitizingmalicious codes. A malicious code can be a stringthatcontains SQL symbols ork- words.Ifan attacker sendarequest with SQL code ('alice'-') - jected "php?username=alice'-", the query becomes "SELECT* FROM users WHERE username='alice'--' AND usertype='user'". Constitutes the refereed proceedings of the 6th International Conference on Information Systems Security, ICISS 2010, held in Gandhinagar, India, in December 2010. Shipping may be from multiple locations in the US or from the UK, depending on stock availability.…

N° de ref. del artículo 9783642177132

Título
Information Systems Security (Paperback)
Autor
Somesh Jha
Editorial
Springer-Verlag Berlin and Heidelberg GmbH & Co. KG, Berlin
Año de publicación
2010
Estado
new
Encuadernación
Paperback
Idioma
inglés
ISBN 10
3642177131
ISBN 13
9783642177132

Grand Eagle Retail

Bensenville, IL, Estados Unidos de America

Vendedor de 5 estrellas

Vendedor de IberLibro desde 12 de octubre de 2005

Tarifas de envío en Estados Unidos de America

ArtículoDe 6 a 14 días hábilesDe 6 a 16 días hábiles
Primer artículoEUR 0,00EUR 0,00
Los plazos de entrega los establecen los vendedores y varían según el transportista y la ubicación. Los pedidos que pasan por la aduana pueden sufrir retrasos y los compradores son responsables de los aranceles o tarifas asociadas. Los vendedores pueden ponerse en contacto con usted en relación con cargos adicionales para cubrir cualquier aumento en los costes de envío de los artículos.

Métodos de pago

  • Visa
  • Mastercard
  • American Express
  • Carte Bleue
  • Apple Pay
  • Google Pay

Información empresarial del vendedor

APOLLO ONLINE CORP.

605 Geddes Street
Wilmington, DE Estados Unidos de America 19805