dc.contributorCorrea Botero, Daniel
dc.contributorVallejo Correa, Paola Andrea
dc.creatorRamos Mena, Ángel Eduardo
dc.date.accessioned2023-05-08T21:20:07Z
dc.date.accessioned2023-08-28T14:09:01Z
dc.date.available2023-05-08T21:20:07Z
dc.date.available2023-08-28T14:09:01Z
dc.date.created2023-05-08T21:20:07Z
dc.date.issued2022
dc.identifierhttp://hdl.handle.net/10784/32437
dc.identifier005.8 R175
dc.identifier.urihttps://repositorioslatinoamericanos.uchile.cl/handle/2250/8441579
dc.description.abstractThe development of technological applications has constantly been evolving to provide a better experience for users, as it can ensure their security to avoid specific threats that could interfere with their actual operation. Despite the efforts, internal and external security threats are present, which is why it is necessary to take all possible precautions to respond to them. Currently, web application frameworks (Web Application Frameworks - WAF) facilitate development and enhance security in web applications. In this work, we focus on how the WAFs Laravel, Express, Spring, and Django, provide mechanisms to implement security in web applications. An application was developed with the MVC (Model - View - Controller) architecture pattern in each of the selected WAFs. Cross-Site Scripting, SQL Injection, and Cross-Site Request Forgery hacking techniques were chosen to alter the applications in an unauthorized manner. These techniques were used to observe how applications can be breached. We also analyzed how prepared WAFs are to deal with these techniques, what rules they incorporate to ensure adequate protection, and how risk can be minimized to make development in a specific WAF more secure.
dc.languagespa
dc.publisherUniversidad EAFIT
dc.publisherMaestría en Ingeniería
dc.publisherEscuela de Ciencias Aplicadas e Ingeniería
dc.publisherMedellín
dc.rightshttp://creativecommons.org/licenses/by/4.0/deed.es
dc.rightsinfo:eu-repo/semantics/openAccess
dc.rightsAcceso abierto
dc.rightsTodos los derechos reservados
dc.subjectXSS
dc.subjectSQL Injection
dc.subjectCSRF
dc.subjectSeguridad
dc.subjectTécnica de hacking
dc.subjectModelo-Vista-Controlador (MVC)
dc.subjectFramework de aplicación web (WAF)
dc.subjectSpring
dc.subjectLaravel
dc.subjectDjango
dc.subjectExpress
dc.titleAnálisis de seguridad de XSS, SQL Injection y CSRF en Laravel, Django, Express y Spring
dc.typemasterThesis
dc.typeinfo:eu-repo/semantics/masterThesis


Este ítem pertenece a la siguiente institución