{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T07:02:05Z","timestamp":1725865325889},"publisher-location":"Cham","reference-count":36,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319465975"},{"type":"electronic","value":"9783319465982"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-46598-2_13","type":"book-chapter","created":{"date-parts":[[2016,9,15]],"date-time":"2016-09-15T18:31:00Z","timestamp":1473964260000},"page":"179-195","source":"Crossref","is-referenced-by-count":4,"title":["Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection"],"prefix":"10.1007","author":[{"given":"Federico","family":"De Meo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marco","family":"Rocchetto","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luca","family":"Vigan\u00f2","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,17]]},"reference":[{"key":"13_CR1","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Barth, A., Lam, P., Mitchell, J., Song, D.: Towards a formal foundation of web security. In: CSF, pp. 290\u2013304. IEEE (2010)","DOI":"10.1109\/CSF.2010.27"},{"key":"13_CR2","unstructured":"Apache software foundation. Apache HTTP Server Tutorial: .htaccess files. https:\/\/httpd.apache.org\/docs\/current\/howto\/htaccess.html"},{"key":"13_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1007\/978-3-642-28756-5_19","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"A Armando","year":"2012","unstructured":"Armando, A., et al.: The AVANTSSAR platform for the automated validation of trust and security of service-oriented architectures. In: Flanagan, C., K\u00f6nig, B. (eds.) TACAS 2012. LNCS, vol. 7214, pp. 267\u2013282. Springer, Heidelberg (2012)"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"B\u00fcchler, M., Oudinet, J., Pretschner, A.: Semi-automatic security testing of web applications from a secure model. In: SERE, pp. 253\u2013262 (2012)","DOI":"10.1109\/SERE.2012.38"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Calvi, A., Vigan\u00f2, L.: An automated approach for testing the security of web applications against chained attacks. In: ACM\/SIGAPP SAC. ACM Press (2016)","DOI":"10.1145\/2851613.2851803"},{"key":"13_CR6","unstructured":"Christey, S.: The 2009 CWE\/SANS Top 25 Most Dangerous Programming Errors. http:\/\/cwe.mitre.org\/top25"},{"key":"13_CR7","unstructured":"CVE-2015-7857. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-7857"},{"key":"13_CR8","unstructured":"CWE. CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u2018SQL Injection\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/89.html"},{"key":"13_CR9","unstructured":"Damele, B., Guimar\u00e3es, A.: Advanced SQL injection to operating system full control. In: BlackHat EU (2009)"},{"key":"13_CR10","unstructured":"De Meo, F., Rocchetto, M., Vigan\u00f2, L.: Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection (Extended Version) (2016). arXiv:1605.00358"},{"issue":"2","key":"13_CR11","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev, D., Yao, A.C.: On the security of public key protocols. IEEE Trans. Inf. Theory 29(2), 198\u2013208 (1983)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"13_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why Johnny can\u2019t pentest: an analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol. 6201, pp. 111\u2013131. Springer, Heidelberg (2010)"},{"key":"13_CR13","unstructured":"Damn Vulnerable Web Application (DVWA). http:\/\/www.dvwa.co.uk"},{"key":"13_CR14","unstructured":"Forristal, J.: ODBC and MS SQL server 6.5. Phrack 8(54) (1998). Article 08"},{"key":"13_CR15","unstructured":"Halfond, W.G., Viegas, J., Orso, A.: A classification of SQL-injection attacks and countermeasures. In: SIGSOFT 2006\/FSE-14 (2006)"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Halfond, W.G.J., Orso, A.: AMNESIA: analysis and monitoring for NEutralizing SQL\u2013injection attacks. In: ASE, pp. 174\u2013183. IEEE (2005)","DOI":"10.1145\/1101908.1101935"},{"key":"13_CR17","unstructured":"Homakov, E.: How I hacked Github again (2014). http:\/\/homakov.blogspot.it\/2014\/02\/how-i-hacked-github-again.html"},{"key":"13_CR18","unstructured":"Internet Engineering Task Force (IETF). HTTP Authentication: Basic and Digest Access Authentication (1999). https:\/\/www.ietf.org\/rfc\/rfc2617.txt"},{"key":"13_CR19","unstructured":"iSpiderLabs. Joomla SQL Injection Vulnerability Exploit Results in Full Administrative (2015). https:\/\/www.trustwave.com\/Resources\/SpiderLabs-Blog\/Joomla-SQL-Injection-Vulnerability-Exploit-Results-in-Full-Administrative-Access\/?page=1&year=0&month=0 . Accessed"},{"key":"13_CR20","volume-title":"Logic, Language, and Analysis","author":"D Jackson","year":"2012","unstructured":"Jackson, D., Abstractions, S.: Logic, Language, and Analysis. MIT Press, Cambridge (2012)"},{"key":"13_CR21","unstructured":"Jayathissa, O.M.: SQL Injection in Insert, Update and Delete Statements"},{"key":"13_CR22","unstructured":"Joomla! https:\/\/www.joomla.org"},{"key":"13_CR23","doi-asserted-by":"crossref","unstructured":"Kie\u017cun, A., Guo, P.J., Jayaraman, K., Ernst, M.D.: Automatic creation of SQL injection and cross-site scripting attacks. In: ICSE, pp. 199\u2013209. IEEE (2009)","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"13_CR24","unstructured":"Livshits, V.B., Lam, M.S.: Finding security vulnerabilities in Java applications with static analysis. In: USENIX, p. 18 (2005)"},{"key":"13_CR25","unstructured":"Martin, M., Lam, M.S.: Automatic generation of XSS and SQL injection attacks with goal-directed model checking. In: USENIX, pp. 31\u201343 (2008)"},{"key":"13_CR26","unstructured":"MySQL. https:\/\/www.mysql.com"},{"key":"13_CR27","unstructured":"OWASP. Owasp top 10 for 2013. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"13_CR28","unstructured":"OWASP. SQL Injection. https:\/\/www.owasp.org\/index.php\/SQL_Injection"},{"key":"13_CR29","unstructured":"OWASP. WebGoat Project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_WebGoat_Project"},{"key":"13_CR30","unstructured":"PostgreSQL. http:\/\/www.postgresql.org"},{"key":"13_CR31","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1007\/978-3-642-55415-5_3","volume-title":"ICT Systems Security and Privacy Protection","author":"M Rocchetto","year":"2014","unstructured":"Rocchetto, M., Ochoa, M., Torabi Dashti, M.: Model-based detection of CSRF. In: Cuppens-Boulahia, N., Cuppens, F., Jajodia, S., Abou El Kalam, A., Sans, T. (eds.) SEC 2014. IFIP AICT, vol. 428, pp. 30\u201343. Springer, Heidelberg (2014)"},{"key":"13_CR32","unstructured":"SQLfast: SQL Formal AnalisyS Tool (2015). http:\/\/regis.di.univr.it\/sqlfast\/"},{"key":"13_CR33","unstructured":"sqlmap: Automatic SQL injection and database takeover tool (2013). http:\/\/sqlmap.org"},{"key":"13_CR34","unstructured":"sqlninja: a SQL Server injection & takeover tool (2013). http:\/\/sqlninja.sourceforge.net"},{"key":"13_CR35","unstructured":"Stampar, M.: Data Retrieval over DNS in SQL Injection Attacks (2013). http:\/\/arxiv.org\/abs\/1303.3047"},{"key":"13_CR36","doi-asserted-by":"crossref","unstructured":"Vigan\u00f2, L.: The SPaCIoS project: secure provision and consumption in the internet of services. In: ICST, pp. 497\u2013498 (2013)","DOI":"10.1109\/ICST.2013.75"}],"container-title":["Lecture Notes in Computer Science","Security and Trust Management"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-46598-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,13]],"date-time":"2019-09-13T11:22:16Z","timestamp":1568373736000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-46598-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319465975","9783319465982"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-46598-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}