摘要
为了提高数据库系统的安全性,及时发现、防范网站中可能存在的SQL注入漏洞,分析了基于SQL注入的渗透性测试技术,在此基础上提出了渗透性测试的原型系统,给出了主要的功能,通过对动网论坛的渗透性测试分析比较了原型系统的效能。实验表明,该原型系统能较好发现系统的SQL注入的脆弱点,从而帮助管理员提升系统的安全性。
In order to improve the security of database system and find the SQL injection vulnerabilities in time, some key penetration testing techniques are discussed and based on which the prototype system of penetration testing is introduced, Then the main functions are given and finally through penetration testing on the objects, efficiency of the prototype system is compared and analyzed. The experiment shows that the prototype system can find SQL injection vulnerabilities effectually and help the administrator to enhance the security.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第15期3577-3579,共3页
Computer Engineering and Design
关键词
渗透测试
SQL注入
代码注入
函数注入
缓冲区溢出
penetration testing
SQL injection
code injection
function call injection
buffer overflow