An analysis of XSS, CSRF and SQL injection in colombian software and web site development
Title | An analysis of XSS, CSRF and SQL injection in colombian software and web site development |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Alvarez, E. D., Correa, B. D., Arango, I. F. |
Conference Name | 2016 8th Euro American Conference on Telematics and Information Systems (EATIS) |
Keywords | Colombian companies, Colombian organizations, Colombian software development, Colombian Web Site development, composability, Computer crime, Cross Site Request Forgery, Cross Site Scripting, Cross Site Scripting attacks, CSRF, Databases, Economics, Hacking, hacking protection, Human Behavior, Internet, pubcrawl, Resiliency, security protocols, Software, Software development, software engineering, SQL, SQL Injection, Web applications, web security, Web sites, websites, XSS |
Abstract | Software development and web applications have become fundamental in our lives. Millions of users access these applications to communicate, obtain information and perform transactions. However, these users are exposed to many risks; commonly due to the developer's lack of experience in security protocols. Although there are many researches about web security and hacking protection, there are plenty of vulnerable websites. This article focuses in analyzing 3 main hacking techniques: XSS, CSRF, and SQL Injection over a representative group of Colombian websites. Our goal is to obtain information about how Colombian companies and organizations give (or not) relevance to security; and how the final user could be affected. |
URL | https://ieeexplore.ieee.org/document/7520140 |
DOI | 10.1109/EATIS.2016.7520140 |
Citation Key | alvarez_analysis_2016 |
- Human behavior
- XSS
- websites
- Web sites
- web security
- web applications
- SQL injection
- SQL
- software engineering
- software development
- Software
- security protocols
- Resiliency
- pubcrawl
- internet
- Colombian companies
- hacking protection
- Hacking
- Economics
- Databases
- CSRF
- Cross Site Scripting attacks
- Cross Site Scripting
- Cross Site Request Forgery
- Computer crime
- composability
- Colombian Web Site development
- Colombian software development
- Colombian organizations