arXiv · 1605.00358
Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection (Extended Version)
Abstract
We present a formal approach that exploits attacks related to SQL Injection (SQLi) searching for security flaws in a web application. We give a formal representation of web applications and databases, and show that our formalization effectively exploits SQLi attacks. We implemented our approach in a prototype tool called SQLfast and we show its efficiency on real-world case studies, including the discovery of an attack on Joomla! that no other tool can find.
Explore related subjects
Keep this discovery
Federico De Meo, Marco Rocchetto, Luca Viganò. 2016-05-02. Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection (Extended Version). https://arxiv.org/abs/1605.00358
Cite the original work for its findings. Save a collection to share your selection of sources.