{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:18:37Z","timestamp":1781104717805,"version":"3.54.1"},"reference-count":32,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,10]]},"abstract":"<jats:p>Lightweight Directory Access Protocol (LDAP) is commonly used in web applications to provide lookup information and enforcing authentication. Web applications may suffer from LDAP injection vulnerabilities that can lead to security breaches such as login bypass and privilege escalation. This paper1 proposes OCL fault injection-based detection of LDAP injection attacks. The authors extract design-level information and constraints expressed in OCL and then randomly alter them to generate test cases that have the capability to uncover LDAP injection vulnerabilities. The authors proposed approaches to implement test case generation, and they used one open source PHP application and one custom application to evaluate the proposed approach. The analysis shows that this approach can detect LDAP injection vulnerabilities.<\/jats:p>","DOI":"10.4018\/ijsse.2017100102","type":"journal-article","created":{"date-parts":[[2018,4,16]],"date-time":"2018-04-16T09:12:29Z","timestamp":1523869949000},"page":"31-50","source":"Crossref","is-referenced-by-count":1,"title":["LDAP Vulnerability Detection in Web Applications"],"prefix":"10.4018","volume":"8","author":[{"given":"Hossain","family":"Shahriar","sequence":"first","affiliation":[{"name":"Kennesaw State University, Marietta, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hisham","family":"Haddad","sequence":"additional","affiliation":[{"name":"Kennesaw State University, Marietta, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pranahita","family":"Bulusu","sequence":"additional","affiliation":[{"name":"Kennesaw State University, Marietta, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSE.2017100102-0","doi-asserted-by":"publisher","DOI":"10.1109\/QSIC.2005.63"},{"key":"IJSSE.2017100102-1","doi-asserted-by":"publisher","DOI":"10.1145\/2351676.2351691"},{"key":"IJSSE.2017100102-2","doi-asserted-by":"crossref","unstructured":"Bulusu, P. (2015, December). Detection of Lightweight Directory Access Protocol Query Injection Attacks in Web Applications [MSCS Thesis]. Kennesaw State University. Retrieved from http:\/\/digitalcommons.kennesaw.edu\/cgi\/viewcontent.cgi?article=1001&context=cs_etd","DOI":"10.1109\/CTS.2015.7210446"},{"key":"IJSSE.2017100102-3","doi-asserted-by":"publisher","DOI":"10.1109\/CTS.2015.7210446"},{"key":"IJSSE.2017100102-4","article-title":"LDAP injection Attack and Defense Techniques.","author":"G.Coldwind","journal-title":"HITB Magazine"},{"key":"IJSSE.2017100102-5","unstructured":"DuPaul, N. (2015). LDAP Injection Guide. Veracode. Retrieved from https:\/\/www.veracode.com\/ldap-injection?mkt_tok=3RkMMJWWfF9wsRoiu6rfLqzsmxzEJ8zx7eUtWbHr08Yy0EZ5VunJEUWy3YYCWoEnZ9mMBAQZC813xR5ZGe%2BReQ%3D%3D"},{"key":"IJSSE.2017100102-6","unstructured":"dzhuvinov. (n.d.). Escaping special characters in LDAP search filters. Retrieved from http:\/\/blog.dzhuvinov.com\/?p=585"},{"key":"IJSSE.2017100102-7","unstructured":"Faust, S. (n.d.). LDAP Injection: Are Your Applications Vulnerable? SPI Labs. Retrieved from http:\/\/www.networkdls.com\/articles\/ldapinjection.pdf"},{"key":"IJSSE.2017100102-8","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2007.55"},{"key":"IJSSE.2017100102-9","doi-asserted-by":"crossref","first-page":"1638","DOI":"10.1145\/2245276.2232038","article-title":"Using Faults for Buffer Overflow Effects","author":"P.Fouque","year":"2012","journal-title":"Proc. of ACM Symposium of Applied Computing"},{"key":"IJSSE.2017100102-10","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2008.02.047"},{"key":"IJSSE.2017100102-11","first-page":"81","article-title":"A Fault Injection Based Approach to Assessment of Quality of Test Sets for BPEL processes","author":"D.Grela","year":"2015","journal-title":"Proceedings of the International Conference on Evaluation of Novel Approaches of Software Engineering (ENASE)"},{"key":"IJSSE.2017100102-12","doi-asserted-by":"publisher","DOI":"10.1145\/1449814.1449912"},{"key":"IJSSE.2017100102-13","doi-asserted-by":"publisher","DOI":"10.1109\/IWSESS.2009.5068460"},{"key":"IJSSE.2017100102-14","unstructured":"Hoyt, D. LDAP Injection Vulnerability in SmarterMail,http:\/\/www.exploit-db.com\/exploits\/15189\/"},{"key":"IJSSE.2017100102-15","unstructured":"IBM Knowledge Center. (n.d.). Injection Attacks. Retrieved from http:\/\/pic.dhe.ibm.com\/infocenter\/sprotect\/v2r8m0\/index.jsp?topic=%2Fcom.ibm.ips.doc%2Fconcepts%2Fwap_injection_attacks.htm"},{"key":"IJSSE.2017100102-16","unstructured":"Microsoft support. (n.d.). Introduction to Lightweight Directory Access Protocol (LDAP). Retrieved from http:\/\/support.microsoft.com\/kb\/196455"},{"key":"IJSSE.2017100102-17","doi-asserted-by":"crossref","unstructured":"Kie\u017cun, A., Guo, P., Jayaraman, K., & Ernst, M. (2008, September). Automatic creation of SQL injection and cross-site scripting attacks (Technical Report MIT-CSAIL-TR-2008-054).","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"IJSSE.2017100102-18","doi-asserted-by":"publisher","DOI":"10.1145\/1529282.1529737"},{"key":"IJSSE.2017100102-19","unstructured":"Open Web Application Security Project (OWASP). (n.d.). LDAP injection. Retrieved from https:\/\/www.owasp.org\/index.php\/LDAP_injection"},{"key":"IJSSE.2017100102-20","unstructured":"OpenLDAP. (n.d.). Security Considerations. Retrieved from http:\/\/www.openldap.org\/doc\/admin24\/security.html"},{"key":"IJSSE.2017100102-21","unstructured":"Oracle. (n.d.). Prepared Statement. Retrieved from http:\/\/docs.oracle.com\/javase\/7\/docs\/api\/java\/sql\/PreparedStatement.html"},{"key":"IJSSE.2017100102-22","first-page":"284","article-title":"Ross,","author":"P.Salas","year":"2007","journal-title":"Proc. of Australian Software Engineering Conference"},{"key":"IJSSE.2017100102-23","first-page":"455","article-title":"OCL Fault Injection Based Detection of LDAP Query Injection Attack","author":"H.Shahriar","year":"2016","journal-title":"Proc. of 40th IEEE International Conference on Computers, Software and Applications Workshop (COMPSACW)"},{"key":"IJSSE.2017100102-24","unstructured":"Stackexchange. (n.d.). SQL Injection example. Retrieved from http:\/\/security.stackexchange.com\/questions\/34655\/is-there-any-sql-injection-for-this-php-login-example"},{"key":"IJSSE.2017100102-25","first-page":"155","article-title":"Syntax-based Vulnerabilities Testing of Frame-based Network Protocols.","author":"O.Tal","year":"2004","journal-title":"Proc. of the 2nd Annual Conf. on Privacy, Security and Trust"},{"key":"IJSSE.2017100102-26","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030088"},{"key":"IJSSE.2017100102-27","author":"J.Voas","year":"2000","journal-title":"Assessing Survivality using Software Fault Injection System (Technical Report# ADP010875)"},{"key":"IJSSE.2017100102-28","unstructured":"Stackexchange. (n.d.). Vulnerable Applications for LDAP Injection. Retrieved from http:\/\/security.stackexchange.com\/questions\/23032\/vuln-web-app-which-includes-ldap-injection"},{"key":"IJSSE.2017100102-29","first-page":"70","article-title":"An Analysis Framework for Security in Web Applications","author":"G.Wassermann","year":"2004","journal-title":"Proceedings of the FSE Workshop on Specification and Verification of Component-Based Systems (SAVCBS 2004)"},{"key":"IJSSE.2017100102-30","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076770"},{"key":"IJSSE.2017100102-31","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606611"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=204523","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,19]],"date-time":"2022-08-19T15:07:42Z","timestamp":1660921662000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSE.2017100102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2017,10]]},"references-count":32,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2017100102","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,10]]}}}