Repository logo
Communities & Collections
All of DSpace
  • English
  • العربية
  • বাংলা
  • Català
  • Čeština
  • Deutsch
  • Ελληνικά
  • Español
  • Suomi
  • Français
  • Gàidhlig
  • हिंदी
  • Magyar
  • Italiano
  • Қазақ
  • Latviešu
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Srpski (lat)
  • Српски
  • Svenska
  • Türkçe
  • Yкраї́нська
  • Tiếng Việt
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. Browse by Author

Browsing by Author "Prof. Elsamani A. talab"

Filter results by typing the first few letters
Now showing 1 - 1 of 1
  • Results Per Page
  • Sort Options
  • Thumbnail Image
    Item
    1 Superglobals Sanitization against SQL injection and XSS
    (جامعة النيلين - كلية الدراسات العليا, 2016) Osman Elnour Sulieman; Mohammed Hassan Ahmed; Prof. Elsamani A. talab; Prof. Awad Alkarim Mohammed Yousif
    SQL injection attack, exploit the problem of insufficient input data validation to trick PHP applications into executing unintended queries that allow hackers to bypass login screen, read, update, alter, create, or even delete sensitive data stored in the backend database. Cross site Scripting-XSS, harness the same problem to access sensitive page contents, session cookies, and a variety of other information retained by the browser on behalf of the user. This problem can be solved by performing static source code analysis to detect taintable points in the code before the application is deployed on the web. In this paper, we present a novel technique depend on reading your PHP source code file line by line and uses regular expressions to precisely find superglobals that hold form parameters, request details, cookies and session information and automatically add a user-defined function named as sanitizer to the source code. The Sanitizer will receive superglobals values to sanitize them against SQL injection and XSS. We implemented our approach in a simple tool called SQL Injection-XSS sanitizer. Our results show that the tool is capable of protecting PHP applications against untrusted input data with high rate.

DSpace software copyright © 2002-2025 LYRASIS

  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify