Security Analysis of Web Open-Source Projects Based on Java and PHP

نویسندگان

چکیده

During website development, the selection of suitable computer language and reasonable use relevant open-source projects is imperative. Although two languages, PHP Java, have been extensively investigated in this context, there are not many security test reports based on their projects. In article, we conducted separate analyses web-related Java. To end, different frameworks services used to design websites experimental attacks 12 popular filters available GitHub, as well investigate Lightweight Directory Access Protocol (LDAP) Firefox browser environment. Using malicious payloads published by Open Web Application Security Project (OWASP) others, Cross-site Scripting (XSS), Local File Inclusion (LFI), SQL injection, LDAP injection performed targets. The results reveal that although PHP-based more vulnerable than Java-based ones, significant room for improvement. Finally, a whitelist-based filtering scheme proposed. This inline attributes label elements so filter has an excellent detection rate while having pass benign payloads. Effective references suggestions web developers also included aid projects, feasible solutions improve performance

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Modularity Index Metrics for Java-Based Open Source Software Projects

Open Source Software (OSS) Projects are gaining popularity these days, and they become alternatives in building software system. Despite many failures in these projects, there are some success stories with one of the identified success factors is modularity. This paper presents the first quantitative software metrics to measure modularity level of Java-based OSS Projects called Modularity Index...

متن کامل

Web Server Security on Open Source Environments

Administering critical resources has never been more difficult that it is today. In a changing world of software innovation where major changes occur on a daily basis, it is crucial for the webmasters and server administrators to shield their data against an unknown arsenal of attacks in the hands of their attackers. Up until now this kind of defense was a privilege of the few, outbudgeted and ...

متن کامل

Introducing "HEALTH" Perspective in Open Source Web-Enginerring Software Projects Based on Project Data Analysis

There are many initiatives of open-source software which have success stories for web engineering such as Apache Tomcat, Apache HTTP Server and Python. Many of these projects have enjoyed wide industry adoption for web-based applications. For the Open Source Software (OSS) community and observer, it is important to determine whether a (new) project initiative is worthwhile, i.e., warrants a clo...

متن کامل

An Empirical Analysis of Software Changes on Statement Entity in Java Open Source Projects

Software projects keep changing all the time. Understanding the nature of the changes can help build higher quality projects. In this paper, the authors studied software changes on a new entity, statement. They found some types of statements are more likely to change than others. Furthermore, the authors studied software changes to fix bugs and also found some types of statements are more likel...

متن کامل

Security Analysis of PHP Encoder

As an open source server-side scripts language, PHP is used more and more widely by Web developers now. Protecting PHP code from being plagiarized is also a hot research issue especially with the rapid development of dynamic web industry and people’s copyright protection consciousness. Usually the developers use PHP encoders to encrypt the PHP codes before selling them out. There are several di...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Electronics

سال: 2023

ISSN: ['2079-9292']

DOI: https://doi.org/10.3390/electronics12122618