ICT740 Applied Cybersecurity

  • Subject Code :  

    ICT740

  • Country :  

    AU

  • University :  

    Kings Own Institute

Answer:-

Task 1: SQL commands 

In this task, the objective will be to get familiar with the commands and related statements of the SQL injection attack to a machine. In this task, a database has been set up which is composed of a table which carries personal information of employees and will be tried to get hands on them as per the following steps.

From the above figure it could be seen that the SQL injection has been initiated with the help of above shown commands.

As it could be observed from the above figure that the use Users command has been initiated and following outcome has been received.

The above figure shows that the required table has been gained regarding the first employee whose name is Alice.

Task 2: SELECT statement SQL injection attack 

SQL injection is the way through which the attackers inject malicious codes to the sensitive data and information of a user. In this task, www.SEEDLabSQLInjection.com has been utilized for logging in page of the employees as shown in the following tasks.

Task 2.1: SQL injection form webpage

It could be seen that the page requires user details such as user name and password.

From the above figure, it could be observed that SQL commands are exploited for entering into the portal as it was required to do in the Task 2.1.

Above is the result gained by SQL command and hence, the SQL injection from webpage is successful.

Task 2.2: SQL injection from command line 

For initiating the task 2.2, a new terminal will be required to open and the (Curl www.SeedLabSQLInjection.com/unsafe_home.php?username=admin%27%20%23) command has been set for which following are the outcomes.

Above is the information and data extracted from the command “curl” and hence the injection from command line is successful.

Task 2.3: Append new statement 

In this task, deletion of statement will be performed from the login page and whatever outcome will be got, it will be observed and shown in the following;

As it could be seen from the above figure that the command, ' 1=1;Delete from credential where name='Ted';# has been placed which means, the deletion of credentials for Ted has been performed.

After running the query, an error has been observed.

Task 3: UPDATE statement SQL injection attack 

There is a vulnerability in system regarding the UPDATE statement, by this means, an employee will be able to modify their profiles after logging in to the page. Th following task will be based on performing attack which could update individual salary, other’s salary and their passwords.

Task 3.1: modification of own salary 

In this part of the report, Alice’s salary will be modified and following are the steps.

It could be observed that employee profile for Alice is tried to open.

It could be observed that the employee profile of Alice has been opened and employee ID, salary, birth, SSN and other details could be accessed.

After clicking on the Edit profile option, Alice’s profile could be edited.

As it could be seen that the command ',salary=600000 where EID=10000;# for changing Alice’s salary has been provided and following are the outcomes,

As it could be seen that Alice’s salary has been updated from previous wage to 600000. Therefore, SQL injection for UPDATE statement is successful.

Task 3.2: modify people’s salary

Salary of Boby will be updated here as per the following,

It could be seen that Boby’s salary has been modified.

Task 3.3: modify passwords

As it could be seen that Boby’s password starts with highlighted digits.

Boby’s password has been changed.

Task 4: countermeasure 

Since, there is presence of vulnerability within the employee portal, countermeasure will be taken to avoid it as per the following;

Above is the unsafe portion.

Unsafe_home is secured.

The portal is checked for confirming,

Account is blocked, therefore, the countermeasure is successful.

Bibliography 

Alenezi, M., Nadeem, M., & Asif, R. (2021). SQL injection attacks countermeasures assessments. Indonesian Journal of Electrical Engineering and Computer Science, 21(2), 1121-1131.

Alwan, Z. S., & Younis, M. F. (2017). Detection and prevention of SQL injection attack: A survey. International Journal of Computer Science and Mobile Computing, 6(8), 5-17.

Basit, N., Hendawi, A., Chen, J., & Sun, A. (2019, February). A learning platform for SQL injection. In Proceedings of the 50th ACM technical symposium on computer science education (pp. 184-190).

Farooq, U. (2021). Ensemble Machine Learning Approaches for Detection of SQL Injection Attack. Tehnički glasnik, 15(1), 112-120.

Jemal, I., Cheikhrouhou, O., Hamam, H., & Mahfoudhi, A. (2020). Sql injection attack detection and prevention techniques using machine learning. International Journal of Applied Engineering Research, 15(6), 569-580.

Tang, P., Qiu, W., Huang, Z., Lian, H., & Liu, G. (2020). Detection of SQL injection based on artificial neural network. Knowledge-Based Systems, 190, 105528.

Tigist, K. (2018). Network Security Threat Vulnerability Prevention System For SQL Injection Attack (Doctoral dissertation).

Uwagbole, S. O., Buchanan, W. J., & Fan, L. (2017, May). Applied machine learning predictive analytics to SQL injection attack detection and prevention. In 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM) (pp. 1087-1090). IEEE.

Are you seeking reliable essay help from academic experts in the UK? At Myassignmenthelp.co.uk, we have searched high and low to recruit the top paper writers in the UK who can provide you with the best assignment help. Most of these professionals have completed their PhDs from top universities in the UK. Therefore, they’re the best at resolving every "Who can do my assignment for me?" query.

These professionals undergo intense training to provide coursework help services within strict deadlines. Hence, you don’t have to waste precious seconds wondering, “Can your experts write my assignment within the deadline?" Instead, rest assured that our experts will consistently deliver top-quality work within the due date.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades