Security Analysis of Web Open-Source Projects Based on Java and PHP
نویسندگان
چکیده
During website development, the selection of suitable computer language and reasonable use relevant open-source projects is imperative. Although two languages, PHP Java, have been extensively investigated in this context, there are not many security test reports based on their projects. In article, we conducted separate analyses web-related Java. To end, different frameworks services used to design websites experimental attacks 12 popular filters available GitHub, as well investigate Lightweight Directory Access Protocol (LDAP) Firefox browser environment. Using malicious payloads published by Open Web Application Security Project (OWASP) others, Cross-site Scripting (XSS), Local File Inclusion (LFI), SQL injection, LDAP injection performed targets. The results reveal that although PHP-based more vulnerable than Java-based ones, significant room for improvement. Finally, a whitelist-based filtering scheme proposed. This inline attributes label elements so filter has an excellent detection rate while having pass benign payloads. Effective references suggestions web developers also included aid projects, feasible solutions improve performance
منابع مشابه
Modularity Index Metrics for Java-Based Open Source Software Projects
Open Source Software (OSS) Projects are gaining popularity these days, and they become alternatives in building software system. Despite many failures in these projects, there are some success stories with one of the identified success factors is modularity. This paper presents the first quantitative software metrics to measure modularity level of Java-based OSS Projects called Modularity Index...
متن کاملWeb Server Security on Open Source Environments
Administering critical resources has never been more difficult that it is today. In a changing world of software innovation where major changes occur on a daily basis, it is crucial for the webmasters and server administrators to shield their data against an unknown arsenal of attacks in the hands of their attackers. Up until now this kind of defense was a privilege of the few, outbudgeted and ...
متن کاملIntroducing "HEALTH" Perspective in Open Source Web-Enginerring Software Projects Based on Project Data Analysis
There are many initiatives of open-source software which have success stories for web engineering such as Apache Tomcat, Apache HTTP Server and Python. Many of these projects have enjoyed wide industry adoption for web-based applications. For the Open Source Software (OSS) community and observer, it is important to determine whether a (new) project initiative is worthwhile, i.e., warrants a clo...
متن کاملAn Empirical Analysis of Software Changes on Statement Entity in Java Open Source Projects
Software projects keep changing all the time. Understanding the nature of the changes can help build higher quality projects. In this paper, the authors studied software changes on a new entity, statement. They found some types of statements are more likely to change than others. Furthermore, the authors studied software changes to fix bugs and also found some types of statements are more likel...
متن کاملSecurity Analysis of PHP Encoder
As an open source server-side scripts language, PHP is used more and more widely by Web developers now. Protecting PHP code from being plagiarized is also a hot research issue especially with the rapid development of dynamic web industry and people’s copyright protection consciousness. Usually the developers use PHP encoders to encrypt the PHP codes before selling them out. There are several di...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Electronics
سال: 2023
ISSN: ['2079-9292']
DOI: https://doi.org/10.3390/electronics12122618