Monday, March 4, 2019
Non violent movement
There is a wide-spread conception in the theory of nation-building that delirium is an final way to express disagreement and overcome injustice as soundly as fight a dictatorship. But the last century has prove the f each(prenominal)aciousness of this conception. Mahatma Gandhi and Martin Luther queer Jr., Nelson Mandela and Dalai Lama and many others devote shown that nonviolence can be more powerful force in defeating oppressive rulers and laws.Their hold waters and actions are examples how oppressors or unjust legislation may be defied by the force of al-Quran and soul rather than by the force of weapons. Gene Sharp summarizes the durability of unbloody actions with such words peaceable action is possible, and is capable of wielding coarse power even against ruthless rulers and military regimes, because it attacks the most vulnerable symptomatic of all hierarchical institutions and governments dependence on the governed (p. 18).Nonviolent action is an application of a very simple truth people do not continuously do what they are told to do, and sometimes they do that which has been forbidden. When people refuse their cooperation, subtract their help, and persist in their disobedience and defiance, they do this to deny their adversarys the basic humankind assistance and cooperation which any government or hierarchical system requires. If they do this collectively through their established independent social institutions or new improvised groupings for a sufficient period of time, the power of that government allow weaken and potentially dissolve.The world history has witnessed the cases when nonviolent means have been chosen over violence for religious or ethical reasons. In some cases, even when pragmatic policy-making considerations were dominant in the select of nonviolent struggle, the movement has taken on certain religious or ethical overtones. This was the case in the campaigns of the Indian National Congress for license from Bri tain in the 1920s, 1930s, and 1940s. Those struggles, often nether Gandhis loss leadership, and also the accomplished rights campaigns in the 1950s and 1960s in the Deep South of the United States, under the leadership of Martin Luther business leader, Jr., are very important.Mohandas KaramchandGandhi, better know as Mahatma Gandhi, is the first-year name that comes to mind when one speaks of nonviolence in the 20th century. His personal magnetism and his action not only had a pro rig effect on Indias modern history, but also provided firm basis for all future nonviolent struggles in the world. Gandhis political philosophy revolve around three key concepts satyagraha (non-violence), sawaraj (home rule), and sarvodaya (welfare of all). Whereas satyagraha was essentially a manoeuvre of achieving political ends by non-violent means, sawaraj and sarvodaya sought to encourage ideas of individual and collective improvement and regeneration. much(prenominal) regeneration, Gandhi in sisted, was demand if India was to rediscover her enduring historical and religious self and change over off British rule. (Andrews, 1949)Perhaps Gandhis best-known act of civil disobedience, known as the second satyagraha (hold fast to the truth) was Salt border district that was taking place in 1930 from12 March to 6 April. It show increasing frustration by Congress at its own impotence and, specifically, the British refusal to give way Dominion status to India. Gandhi chose the hated salt tax revenue as the object of his campaign. At the time, the Indian government maintained a monopoly over the manufacture of salt, an essential basic commodity which was thus intemperately taxed. Those using their own salt, e.g. if they were living close to the sea, were subject to heavy punishment.The 61-year-old Mahatma started the 240-mile-long marching music from Sabarmati to the coastal town of Dandi to repairher with seventy-eight of his followers. He was joined by thousands along t he way, in a march that received vast internationalist and national attention. When the protesters marched on to a government salt depot, he was arrested, as were between 60,000 and 90,000 other Indians in subsequent months, as well as the entire Congress leadership. Gandhi was released and cal take off the campaign in March 1931 pursuit the GandhiIrwin Pact, which allowed Gandhi to participate in the second Round Table Conference, and symbolically permitted the doing of salt for domestic consumption.From the 1920s to early 1940s, he guide a series of passive resistance campaigns in pursuit of Swaraj, which redefined the character of Indian nationalism. He sought tolerance between Hindus and Muslims and the eradication of caste untouchability. In January 1948 he was assassinated by a Hindu fanatic for his pro-Muslim sympathies. Gandhis insistence that means were more important than the ends distinguished him from other bulky political leaders of the twentieth century.Since his death Gandhi has become the source of consumption for non-violent political movements such as the civil Rights Movement in the USA. Desmond tutu in the article A Force More Powerful a Century of Nonviolent employment rightfully points out The leaders who opted for nonviolent weapons often l earn from resistance movements of the past. Indian nationalist leader Mohandas Gandhi was stir by the Russian Revolution of 1905. The Rev. Martin Luther fag, Jr. and other African American leaders traveled to India to study Gandhis tactics. (Tutu, 2000) Non-cooperation was a major tactic employed by Gandhi when he felt the state had become abominable or unjust.In the King movement, such action was called boycott, the most effective nonviolent tactic employed in the movement to abolish discrimination in public transportation in Montgomery, Alabama. The justification for such action lies in the fact that rejection is as much of an action as acceptance. Thus, King, like Gandhi, while emphas izing the necessity of courage, utilized the boycott to achieve rejection of unjust laws modulate public transportation and public lunch counters.The net effect of the unlike expressions of the nonviolent protest, especially the boycott, strike, demonstration and jail, was to draw ones opponent off balance, hoping thereby to change his mind. (Smith, p.58) Nonviolence, therefore, was not a sign of helplessness or of a lack of courage. Quite the contrary, King believed that only the fond and courageous person could be nonviolent. He advised persons not to get involved in the civil rights struggle unless they had the strength and the courage to bag before people full of hate and to break the cycle of violence by refusing to retaliate.King just as Gandhi emphasized the need to prepare for action. The Civil Rights Movement initiated by Martin Luther King, Jr. succeeded in mobilizing massive nonviolent say action. Innovative tactics included economic boycotts, beginning with the yea rlong boycott of a bus company in Montgomery, Alabama, begun in December 1955 and led by Martin Luther King, Jr. sit-in demonstrations and mass marches, including a massive mobilization of ashens and blacks in the August 1963 March on Washington, which culminated in Kings I have a dream speech, and protest marches led by King that met with police violence in Selma, Alabama, in January 1965.The finis of these protests was to overthrow the entire system of racial segregation and to empower African Americans by seizing the franchise. Participants of the Civil Rights Movement were often beaten and brutalized by southern law enforcement officials, and thousands were arrested and jailed for their protest activities. Some leaders and participants were killed.Nevertheless, an dateless stream of highly visible confrontations in the streets, which contrasted the brutality and the inhumanity of the white segregationists with the dignity and resolve of black protesters, made the cause of bl ack civil rights the major issue in the United States for over a go during the 1950s and 1960s. The nation and its leaders were forced to decide publicly whether to grant African Americans their citizenship rights or to side with white segregationists who advocated racial superiority and the tyrannic subjugation of black people.In conclusion it would be relevant to provide a brief revision of the similarity and differences the detection of which was purpose of this analysis. The parallels between Gandhi and Martin Luther King are self-evident. This preliminary look at Gandhi and Kings performance gives us the understanding that nonviolent movement cannot be limited by time frames or specific location. It rather call for a leader with toilsome character, resilience and ability to persuade people. The two leaders preferred nonviolence at a time when their people were being oppressed. both(prenominal) struggled against the yoke of white oppression. Like Gandhi, King valued the p ower of nonviolent political action in keeping with the spirit of Gandhis satyagraha. Kings role in organizing the Montgomery bus boycott enabled him to come forth as the creator of a strategy of civil disobedience that earned for the civil-rights movement in the United States unprecedented media coverage, new forms of public recognition, and greater access to political power.Though both agreed that nonviolence is successful tactics on condition that every individual is committed to truth and justice, Gandhi tended to flummox stress upon the necessity of personal suffering when participating in nonviolent movement, an attitude that to some extent was less aggressive than Kings emphasis on self-sacrifice. Moreover, Gandhi claimed that to achieve the goals through nonviolence one needs patience and non-cooperation and King believed that it is a certain degree of confrontation that is necessary to accomplish change. One more difference between Gandhi and King lies in the paradigm of their activity.While Gandhi was concerned about social injustice suffered by Indian people, Kings concerns bore upon racial discrimination of African Americans in the USA. And probably the most striking difference is the result of their struggle. While Martin Luther Kings ideas after his death were followed through by his followers and found an echo in common Americans heart, Gandhi was criticized that his tactics unnecessarily delayed the departure of the British, precipitated the partition of India, and led to the Hinduization of Congress because of his over-emphasis on religion. few of Gandhis ideas were put into practice by independent India.While both of them be respect and admiration, it is possible to recognize that their approaches to the practice of nonviolence later grew strong one as opposition, the other as protest. Gandhi and King help us to believe that peaceful resolution of a conflict will live up to its promise.ReferencesAndrews, C. F. Mahatma Gandhis Ideas. London Allen & Unwin, 1949McCarthy, R. and Sharp, G., eds., Nonviolent Action A look Guide. New York, 1997Sharp, G. The Role of Power in Nonviolent Struggle. Monograph Series, No. 3. The Albert sensation Institution, 1990Smith, Kenneth and Zepp, Ira. Search for the Beloved Community The Thinking of Martin Luther King. Valley Forge Judson Press, 1974.Tutu, Desmond. A Force More Powerful a Century of Nonviolent Conflict. Social Education. (64)5, 2000
Sunday, March 3, 2019
Rhetorical Devices Essay
The definition of an anecdote is a story that is very pitiable that either explains or emphasizes a point that is trying to be made. In my speech when I was explaining that soccer has affected the paths that my life has taken including schools and friends, I used the short story of getting recruited for soccer at the tall school and collegiate level, which is also where I met my best friends. In Bekah Diehls speech making the point that the saying the only headache is fear itself she say she not scared of the fear of base lubbers, but rather the ball itself. The story she used was with her friends playing catch with the baseball around her.The refinement is the final part of a speech that closes it and ties it all main points together. In the conclusion the thesis is stated, the main points are summarized, and a clincher is said to leave the audience with. The conclusion for my speech was that soccer has made me a well-rounded individual and has shaped the person that I am today . My preferred memories hold included playing soccer and my teammates. When I step on the field I am free. I would not be the corresponding person today if soccer was not in my life. In the culmination of Bekah Diehl her conclusion that was her fear of baseballs is real and something she has to deal with. However, she takes comfort that her she doesnt have a phobia of something else and that her phobia could be of something worse.
The Important Things
The Important Things What be the most important things in my flavor? Family is the number one most important thing in my spiritedness. My girlfriend, education, c areer, capital and happiness are also precise important to me in life. Without my family I wouldnt be the person I am today. I couldnt ask for better parents. And I have a little fellow I wouldnt be able to live without. My parents travel in truth life-threatening to provide a wonderful life for us. We really transport going camping and taking other vacations together. It gives us a smoke of quality time to spend together.My family helps me through the saturated times in life. I have the ruff grandparents in the world that would do anything for me. I have been precise fortunate being able to spend mussiness of time with them while growing up. We have made many finical memories together that I provide always hold close to my heart. thither were six cronys and sisters on my dads side and four sisters on my m oms side. Combining the two, I have twelve stupefying cousins. We are all actually close and get together to hold back all of the birthdays and holidays.I have sex my family with all my heart and could neer ask for a better one. My girlfriend means the world to me. Not only is she my girlfriend, she is my shell friend. She knows how to make me smile when Im not in a good mood. She is the one person I know I jackpot count on. I applaud her with all my heart. I will neer let her go. We have been together since the beginning of high school. We have a particular(prenominal) connection with each other there is something that will neer break us apart. Education is a very important showcase in my life.Getting laid off for the second winter really inspire me to go back to school. I am now in a four semester program to become a Process Operator. Lewis and Clark provide a great education. I have been laming hard and keeping my grades up so that I post graduate on time and spr ightliness for a better job. My career is what I am working hard in school for now. The right job is out there for me somewhere. later on I complete my education, I will find it. I am very determined. I feel that being younger I faculty have some advantages. My oal is to get hired on at Phillips 66. They will be hiring for the foreseeable future. Nine out of twenty people were hired from the last class that graduated from the program that I am in now. My cousin was one of them. Can property buy happiness? or so people are extremely wealthy but also very lonely, while others are poor but able with their surrounding family and friends they have. You washstand buy many things with specie but not happiness. on that point are many ways to obtain cash. whatsoever people may work for it while others efficacy win the lottery.I am the type of person who whole caboodle hard for my money and saves it. The more money I have getable the happier I am with myself. I dont let money take over my life though. I have a cover over my head and a meal to eat every night, so for that I am very smart. Being around my family and girlfriend is what real brings happiness to my heart. The most important thing is to honor your life. Being happy is all that truly matters. Hold close those who are close to your heart. The love of family and the admiration of friends are much more important than wealth or privilege.The Important ThingsThe Important Things What are the most important things in my life? Family is the number one most important thing in my life. My girlfriend, education, career, money and happiness are also very important to me in life. Without my family I wouldnt be the person I am today. I couldnt ask for better parents. And I have a little brother I wouldnt be able to live without. My parents work very hard to provide a wonderful life for us. We really enjoy going camping and taking other vacations together. It gives us a lot of quality time to spend toget her.My family helps me through the hard times in life. I have the best grandparents in the world that would do anything for me. I have been very fortunate being able to spend scores of time with them while growing up. We have made many special memories together that I will always hold close to my heart. There were six brothers and sisters on my dads side and four sisters on my moms side. Combining the two, I have twelve frightening cousins. We are all very close and get together to watch over all of the birthdays and holidays.I love my family with all my heart and could neer ask for a better one. My girlfriend means the world to me. Not only is she my girlfriend, she is my best friend. She knows how to make me smile when Im not in a good mood. She is the one person I know I put forward count on. I love her with all my heart. I will never let her go. We have been together since the beginning of high school. We have a special connection with each other there is something that wil l never break us apart. Education is a very important guinea pig in my life.Getting laid off for the second winter really animate me to go back to school. I am now in a four semester program to become a Process Operator. Lewis and Clark provide a great education. I have been working hard and keeping my grades up so that I can graduate on time and nip for a better job. My career is what I am working hard in school for now. The right job is out there for me somewhere. later I complete my education, I will find it. I am very determined. I feel that being younger I might have some advantages. My oal is to get hired on at Phillips 66. They will be hiring for the foreseeable future. Nine out of twenty people were hired from the last class that graduated from the program that I am in now. My cousin was one of them. Can money buy happiness? Some people are extremely wealthy but also very lonely, while others are poor but happy with their surrounding family and friends they have. You can buy many things with money but not happiness. There are many ways to obtain money. Some people may work for it while others might win the lottery.I am the type of person who deeds hard for my money and saves it. The more money I have available the happier I am with myself. I dont let money take over my life though. I have a chapiter over my head and a meal to eat every night, so for that I am very happy. Being around my family and girlfriend is what truly brings happiness to my heart. The most important thing is to enjoy your life. Being happy is all that truly matters. Hold close those who are close to your heart. The love of family and the admiration of friends are much more important than wealth or privilege.
Saturday, March 2, 2019
Infinite Person Essay
I think that people like sire Teresa to me is a perfect example of a infinite person.She give us all a new meaning to life. She rightfully proved that 1 person can really make a difference in the lives of millions. Mother Teresa set examples for future generations to continue her work.This shows how much of an impact she truly had. She made a difference, not by jockstraping everyone, but by making people stop and realize how they could do the same. It should be instilled in our sees that we have a duty to help and serve others.If we as a hole took the examples of Mother Teresa and followed them our society would be a much unwrap place. She went to countries with no medical care, no food, no drinking water, and never mind other necessities. Mother Teresa used her power of love from God to help those in desperate need. Mother Teresa didnt get paid for anything she did nor would she only money from organizations or donations.It was not like Mother Teresa had an overwhelming numb er of money but she was simply a person who devoted her wide life to serving others and helping those in need. Many people whitethorn not have noticed it, but all Mother Teresa had to do was touch a person and that was almost enough. She helped thousands of people in miserable countries with ailing diseases, but most importantly see touched the souls of leafy vegetable men. She made even the rich and selfish take a fatheaded look into their lives, which brought out the best in everyone.
Ethics and Business Practice
One of the m some(prenominal) ch everyenges cladding businesses today is how to harmonize their organization, work and professional ethical motive in delineate with the prevailing business practices and environment. Beckton Dickinson lies mingled with a rock and a warm place. They would motive to carryout their business activities strictly adhering to not only their organizations policies and ethics but also the stipulations by the US government that vehemently outlaw any form of corruption or graft.The US laws on international trade made it illegal for any multinational in operation(p) both at home or in foreign territories, to guide in any malpractice that seeks to trance a decision by any government, institution or individual. Many multinationals especially in Eastern Europe, Asia and Africa where in that respect no stringent laws on tendering, deliver been known to give kickbacks to influence the process. The individuals and the key decision makers behind tendering ar e also known to look for gifts and kickbacks so that they would favor a specific come with. These gifts or commissions may govern from a small gift to a colossal amount of m 1y.Beckton Dickinson centering team strives to maintain high standards that embrace lividity and honesty, and render knowing a guide advocating for the same. They have issued clear guidelines to their employees detailing the callers expectations on the proper conduct and business practice both inside the United States and globally. This guide touches on the issues ranging from political contribution to what is considered to be a gift. The employees have raised their reservations on these guidelines and would wish the amount in involve to what is acceptable in terms of gifts to be defined according to the regions involved.Kickbacks and bribery as indicated in this report is not only a task limited to any specific corporation, industry or government. It is a everyday problem that equally requires global attention. It has permeated every aspect of business bearing and practice. An analyses of the problem would reveal that almost all the parties involved play a role in perpetrating the vice. The big corporations are in business and would want to under all cost secure the most profitable deals. Beckton Dickinson would in no doubt wish to expand its sales and maintain its grocery leadership position in supplying health sector appliances.To lionise its competitor a bay it might be forced to take in in malpractices to secure the contracts. The tendering individuals also may be asking for bribes as well as the government officials. This problem hence is not perpetrated by a single party but by almost all the players. World opinion of late seem to be tilting towards unanimity in the need to establish strict anti-corruption laws in the procural departments. Bribery is a vice that leads to morals and societal degeneration. In confathering this vice the perpetrators are clayey the socia l good.The principle of integrity, fairness and honesty are being threatened. It is authoritative that go be taken to curb this menace to ensure that fairness thrives. Small businesses are being threatened, as some of them terminatenot afford the bribes and kickbacks. at that place should be strict adherence to business ethics to level the playacting field and ensure fair competition. Performance expectations gap is the gap that exists between what the society and shareholders expect the company to deliver in terms of proceeding and what it (company) actually delivers (www. abrema. net).The shareholder and the state have insisted on the adherence to the stipulated laws as far as proper business ethics is concerned. The accountants and auditors of Beckton Dickinson are having it rough in and are in a dilemma as far as accounting fro the gifts and the kickbacks is concerned. The company has issued clear guidelines on the require business ethics. It is advocating for authorizat ion compliances on the side of the employees. The employees especially the personnel on the ground rubric the situation is hostile and tends to lean more on bribery and kickbacks.If you dont pay for the gifts, the rival companies go away do it and clinch the tender. The company has not been able to harmonize its ethics to encompass all levels of its trading operations. in that location should be distinct guidelines in the different regions. Whereas some gifts may be considered ethical in for example the United States, in Japan it is a different story altogether. The company should not abet bribery in some countries while being strict in others. However the juvenile steps taken by the company is a positive index finger that even though the problem is serious, the organization is taking bold steps to curb it.The top management has flown into the regional branches to train the personnel and fierceness on the companies stand as far as business ethics are concerned. The trend is n ot expected to convert overnight. Gradually the company will achieve its key objective and instill discipline in this workforce. The situation though in the internationals scene will take abundant to change. The remedy to curbing this unethical practice requires a multifaceted blast, an approach that will encompass all the players involved. There are different approaches that can be taken in this.Some scholars claim that the big corporations are to blame, having recognized a weakness especially in the developing countries systems of governance they have been known to use all manners of strategies ranging from intimidation to bribery. Hence in ending those unethical practices, corporations have to be at the forefront. Self-regulation of these companies has to be emphasized, change must come from within rather than without (www. newstarget. com) compliance with the ethical guidelines by Beckton Dickinson is a step in the right direction and should be emulated by other players in t he industry.The key to unlocking this ethical deadlock however, many will agree, lies in the government structures and policies themselves. The United States for example issued the stipulations on business practices and ethics as far as bribery and kickbacks are concerned. This greatly cut back the cases as bribery as corporations can now be go about with legal actions upon contravention of the rules. It is upon the governments as the key decision makers, to streamline their procurement rules to ensure fairness, transparency and accountability. Legal redress should be provided to the aggrieved parties.Although the corporations and the society have a role to play the governments hold the key and should be the one to initiate this change and ensure stiff penalties to the defaulters. Reference Dani Veracity, Bribery in medicine how drug authorities, Big pharmapushers and other medical racket operations forfeit ethics for powers and profits. Last updated on January 10,2006. Retrieved in 23/09/07 from http//www. newstarget. com/016676. hypertext markup language ABREMA. Activity based risk evaluation model of auditing. Retrieved on 23/09/07 from http//www. abrema. net/abrema/expec-gap-ag. html
Friday, March 1, 2019
An Approach to Detect and Prevent Sql Injection Attacks in Database Using Web Service
IJCSNS International daybook of physical bodyr Science and mesh tribute, VOL. 11 no. 1, January 2011 197 An Approach to get word and Pr regular(a)t SQL stab Attacks in Database exploitation Web help IndraniBalasundaram 1 Dr. E. Ramaraj2 1 Lecturer, Department of computing device Science, Madurai Kamaraj University, Madurai 2 Director of calculator sum of m stary Alagappa University, Karaikudi. Abstract SQL interfereion is an gust methodology that targets the selective information residing in a infobase done with(predicate) the firew wholly that shields it. The flack catcher takes advantage of poor foreplay administration in rule and ebsite administration. SQL shooter Attacks occur when an assailant is able to insert a series of SQL statements in to a doubt by manipulating exploiter stimulant drug selective information in to a entanglement- found operation, attacker rear supplant take advantages of net action programming security flaws and pass unex pected catty SQL statements through a web operation for execution by the backend database. This paper counsels a novel specification-based methodology for the vetoion of SQL injection Attacks. The both(prenominal) near grievous advantages of the spic-and-span approaching against xisting analogous mechanisms atomic n drinking chocolate 18 that, first, it prevents all forms of SQL injection attacks second, online technique does not al imprint the exploiter to b separate database right off in database waiter. The innovative technique Web profit orientated XPATH Au sotication proficiency is to find out and prevent SQLInjection Attacks in database the deployment of this technique is by generating functions of two filtration models that argon dissembleive follow and Service Detector of masking scripts additionally allowing unseamed integration with currently-deployed transcriptions. General TermsLanguages, Security, Verification, Experimentation. Keywords D atabase security, world-wide web, web exertion security, SQL injection attacks, Run fourth dimension Monitoring changes to data. The affright of SQL injection attacks has become increasingly frequent and serious. . SQL-Injection Attacks atomic number 18 a mark of attacks that m any of these systems ar highly vulnerable to, and on that exhibit is no cognize fool-proof substantiate against such(prenominal) attacks. Comp read-only storageise of these web applications represents a serious brat to organizations that have deployed them, and also to substance absubstance ab drug users who trust these systems to store hidden data. The Web applications hat are vulnerable to SQL-Injection attacks user introduces the attackers embeds overlooks and gets executed 4. The attackers directly door the database underlying an application and leak or transform confidential in coiffureion and execute malicious compute 12. In most cases, attackers even use an SQL Injection exposure to take control and corrupt the system that hosts the Web application. The increasing number of web applications falling prey to these attacks is alarmingly high 3 obstruction of SQLIAs is a major challenge. It is difficult to pass and enforce a rigorous defensive tag discipline. Many olutions based on defensive coding address only a subset of the attainable attacks. Evaluation of Web Service Oriented XPATH Au sotication technique has no inscribe adaption as swell as automation of detective work and prevention of SQL Injection Attacks. Recent U. S. indus deform regulations such as the Sarbanes-Oxley Act 5 pertaining to information security, try to enforce strict security compliance by application vendors. 1. Introduction 1. 1 SAMPLE APPLICATION Information is the virtually important business asset in todays surround and achieving an appropriate take aim of Information Security. SQL-Injection Attacks (SQLIAs) re one of the topmost threats for web application security. For m odelling financial fraud, theft confidential data, deface website, sabotage, espionage and cyber terrorism. The valuation process of security tools for detection and prevention of SQLIAs. To pass security guidelines inside or outside the database it is recommended to access the handsome databases should be superviseed. It is a hacking technique in which the attacker adds SQL statements through a web applications arousal palm or hidden parameters to gain access to resources or make applications programme that contain SQL Injection exposure.The example refers to a fairly simple vulnerability that could be prevented exploitation a straightforward coding fix. This example is hardly apply for illustrative purposes because it is easy to understand and general enough to deck many un desire types of attacks. The code in the example uses the introduce parameters LoginID, news to energetically build an SQL call into question and submit it to a database. For example, if a user s ubmits loginID and password as secret, and 123, the application dynamically builds and submits the examination Manuscript trustworthy January 5, 2011 Manuscript revised January 20, 2011 198IJCSNS International ledger of Computer Science and meshwork Security, VOL. 11 No. 1, January 2011 pick out * from FROM loginID=secret AND pass1=123 user_info WHERE If the loginID and password be the check entry in the database, it pass on be redirect to user_main. aspx page other wise it result be redirect to error. aspx page. 1. dim loginId, countersignature as string along 2. loginId = Text1. Text 3. password = Text2. Text 3. cn. open() 4. qry=select * from user_info where LoginID= & loginID & and pass1= & password & 5. cmd=new sqlcommand(qry,cn) 6. rd=cmd. executereader() 7. if (rd. Read=True) Then 8. Response. redirect(user_main. spx) 9. else 10. Response. redirect(error. aspx) 11. end if 12. cn. close() 13. cmd. dispose() b. Union Query In substance-query attacks, Attackers do this by injecting a statement of the form UNION contract because the attackers tout ensemble control the second/injected query they can use that query to opine information from a specified table. The result of this attack is that the database returns a dataset that is the union of the results of the original first query and the results of the injected second query. Example An attacker could inject the text UNION call for pass1 from user_info where LoginID=secret - nto the login house, which produces the following query SELECT pass1 FROM user_info WHERE loginID= UNION SELECT pass1 from user_info where LoginID=secret AND pass1= Assuming that there is no login allude to , the original first query returns the null set, whereas the second query returns data from the user_info table. In this case, the database would return column pass1 for account secret. The database takes the results of these two queries, unions them, and returns them to the application. In many applications, t he effect of this operation is that the tax for pass1 is displayed along with the account informationFigure 1 Example of . NET code implementation. 1. 2 Techniques of SQLIAS Most of the attacks are not in isolated they are use together or sequentially, depending on the specific goals of the attacker. a. Tautologies Tautology-based attack is to inject code in one or more conditional statements so that they always evaluate to true. The most common usages of this technique are to bypass au indeedtication pages and extract data. If the attack is successful when the code either displays all of the returned records or realizes some execute if at least one record is returned. Example In this example attack, an attacker submits or 1=1 -The Query for Login mode is SELECT * FROM user_info WHERE loginID= or 1=1 AND pass1= The code injected in the conditional (OR 1=1) transforms the entire WHERE clause into a tautology the query evaluates to true for for each one row in the table and re turns all of them. In our example, the returned set evaluates to a not null care for, which causes the application to conclude that the user au accordinglytication was successful. Therefore, the application would invoke method user_main. aspx and to access the application 6 7 8. c. Stored Procedures SQL Injection Attacks of this type try to execute stored single- judged functions present in the database.Today, most database vendors ship databases with a precedent set of stored procedures that extend the functionality of the database and allow for moveion with the operating system. Therefore, once an attacker determines which backend database is in use, SQLIAs can be crafted to execute stored procedures provided by that specific database, including procedures that interact with the operating system. It is a common misconception that using stored procedures to write Web applications renders them protected to SQLIAs. Developers are practically surprised to dislodge that their st ored procedures can be middling as vulnerable o attacks as their normal applications 18, 24. Additionally, because stored procedures are oft successions written in special scripting languages, they can contain other types of vulnerabilities, such as buffer over unravels, that allow attackers to run arbitrary code on the server or escalate their privileges. CREATE PROCEDURE DBO. UserValid(LoginID varchar2, pass1 varchar2 AS EXEC(SELECT * FROM user_info WHERE loginID= emailprotected+ and pass1= emailprotected+ )GO Example This example demonstrates how a parameterized stored procedure can be exploited via an SQLIA. In the example, we assume that the query string constructed at ines 5, 6 and 7 of our example has been replaced by a call IJCSNS International ledger of Computer Science and Network Security, VOL. 11 No. 1, January 2011 to the stored procedure delimit in Figure 2. The stored procedure returns a true/false value to indicate whether the users credentials authenticated corr ectly. To launch an SQLIA, the attacker obviously injects ending into either the LoginID or pass1 fields. This injection causes the stored procedure to pass the following query SELECT * FROM user_info WHERE loginID=secret AND pass1= SHUTDOWN -At this point, this attack works like a piggy-back attack.The first query is executed normally, and then the second, malicious query is executed, which results in a database shut down. This example shows that stored procedures can be vulnerable to the same range of attacks as traditional application code 6 11 12 10 13 14 15. d. Extended stored procedures IIS(Internet Information Services) Reset There are several across-the-board stored procedures that can cause permanent damage to a system19. Extended stored procedure can be executed by using login form with an injected command as the LoginId LoginIdexecmaster.. xp_xxx-PasswordAnything LoginIdexecmaster.. p_cmdshelliisreset-PasswordAnything select password from user_info where LoginId= exec master.. xp_cmdshell iisreset and Password= This Attack is utilize to barricade the answer of the web server of particular Web application. Stored procedures primarily comprise of SQL commands, while XPs can provide entirely new functions via their code. An attacker can take advantage of extended stored procedure by entering a suitable command. This is possible if there is no proper introduce validation. xp_cmdshell is a built-in extended stored procedure that allows the execution of arbitrary command lines. For example exec master.. p_cmdshell dir depart obtain a directory listing of the current running(a) directory of the SQL waiter process. In this example, the attacker may try entering the following input into a search form can be used for the attack. When the query string is parsed and sent to SQL Server, the server will process the following code SELECT * FROM user_info WHERE input text = exec master.. xp_cmdshell LoginId /DELETE 199 Here, the first single quote entered by the user closes the string and SQL Server executes the next SQL statements in the batch including a command to scratch a LoginId to the user_info table in the database. . hang on Encodings Alternate encryptions do not provide any unique way to attack an application they are simply an enabling technique that allows attackers to evade detection and prevention techniques and exploit vulnerabilities that might not otherwise be exploitable. These escapism techniques are often necessary because a common defensive coding practice is to scan for original known bad shells, such as single quotes and comment operators. To evade this defense, attackers have employed alternate methods of encoding their attack strings (e. g. , using hex, ASCII, and Unicode character encoding).Common scanning and detection techniques do not try to evaluate all specially encoded strings, thus allowing these attacks to go undetected. Contributing to the problem is that varied forms in an applicat ion have different ways of handling alternate encodings. The application may scan for certain types of escape characters that represent alternate encodings in its language domain. Another layer (e. g. , the database) may use different escape characters or even solely different ways of encoding. For example, a database could use the expression char(120) to represent an alternately-encoded character x, but char(120) has no special meaning in the application languages context. An rough-and-ready code-based defense against alternate encodings is difficult to implement in practice because it requires developers to consider of all of the possible encodings that could affect a given query string as it passes through the different application layers. Therefore, attackers have been very successful in using alternate encodings to moderate their attack strings. Example Because every type of attack could be represent using an alternate encoding, here we simply provide an example of how dee p an alternativelyencoded attack could appear.In this attack, the following text is injected into the login field secret exec(0x73687574646f776e) . The resulting query generated by the application is SELECT * FROM user_info WHERE loginID=secret exec(char(0x73687574646f776e)) AND pass1= This example makes use of the char() function and of ASCII hex encoding. The char() function takes as a parameter an integer or hexadecimal encoding of a character and returns an instance of that character. The stream of numbers in the second part of the injection is the 200 IJCSNS International daybook of Computer Science and Network Security, VOL. 11 No. , January 2011 ASCII hexadecimal encoding of the string SHUTDOWN. Therefore, when the query is interpreted by the database, it would result in the execution, by the database, of the SHUTDOWN command. References 6 f. Deny Database service This attack used in the websites to issue a denial of service by shutting down the SQL Server. A mighty co mmand recognized by SQL Server is SHUTDOWN WITH NOWAIT 19. This causes the server to shutdown, direct city blockping the Windows service. After this command has been issued, the service must be manually restarted by the administrator. select password from user_info whereLoginId=shutdown with nowait and Password=0 The character date is the single line comment sequence in Transact SQL, and the character denotes the end of one query and the beginning of another. If he has used the default sa account, or has acquired the required privileges, SQL server will shut down, and will require a restart in order to function again. This attack is used to stop the database service of a particular web application. Select * from user_info where LoginId=1xp_cmdshell format c/q /yes drop database mydb AND pass1 = 0 This command is used to format the C drive used by the ttacker. 2. Related Work There are existing techniques that can be used to detect and prevent input manipulation vulnerabiliti es. 2. 1 Web Vulnerability Scanning Web vulnerability scanners crawl and scan for web vulnerabilities by using software agents. These tools perform attacks against web applications, usually in a black-box fashion, and detect vulnerabilities by law-abiding the applications response to the attacks 18. However, without exact knowledge about the internal structure of applications, a black-box approach might not have enough test cases to observe existing vulnerabilities and also have alse positives. 2. 2 Intrusion Detection constitution (IDS) Valeur and colleagues 17 propose the use of an Intrusion Detection System (IDS) to detect SQLIA. Their IDS system is based on a machine learning technique that is train using a set of usual application queries. The technique builds models of the typical queries and then monitors the application at runtime to identify queries that do not match the model in that it builds expected query models and then checks dynamically-generated queries for com pliance with the model. Their technique, however, like most techniques based on learning, can generate large umber of false positive in the absence of an optimal training set. Su and Wassermann 8 propose a solution to prevent SQLIAs by analyzing the parse tree of the statement, generating custom-made validation code, and wrapping the vulnerable statement in the validation code. They conducted a study using five real world web applications and use their SQLCHECK wrapper to each application. They found that their wrapper stopped all of the SQLIAs in their attack set without generating any false positives. While their wrapper was effective in preventing SQLIAs with modern attack structures, we hope to shift the focus rom the structure of the attacks and onto removing the SQLIVs. 2. 3 Combined Static and Dynamic Analysis. memory loss is a model-based technique that combines static compend and runtime monitoring 17. In its static phase, AMNESIA uses static summary to build models of the different types of queries an application can de jure generate at each point of access to the database. In its dynamic phase, AMNESIA intercepts all queries before they are sent to the database and checks each query against the statically built models. Queries that violate the model are identified as SQLIAs and prevented from executing on the database.In their evaluation, the authors have shown that this technique performs well against SQLIAs. The primary demarcation line of this technique is that its success is dependent on the accuracy of its static synopsis for building query models. Certain types of code obfuscation or query development techniques could make this step less precise and result in both false positives and false negatives Livshits and Lam 16 use static analysis techniques to detect vulnerabilities in software. The basic approach is to use information flow techniques to detect when tainted input has been used to construct an SQL query. These ueries are then fl agged as SQLIA vulnerabilities. The authors demonstrate the viability of their technique by using this approach to find security vulnerabilities in a benchmark suite. The primary limitation of this approach is that it can detect only known patterns of SQLIAs and, IJCSNS International Journal of Computer Science and Network Security, VOL. 11 No. 1, January 2011 because it uses a ultraconservative analysis and has limited retain for untainting operations, can generate a comparatively high amount of false positives. Wassermann and Su propose an approach that uses static analysis combined with automated reasoning to verify that he SQL queries generated in the application layer cannot contain a tautology 9. The primary drawback of this technique is that its stretch is limited to detecting and preventing tautologies and cannot detect other types of attacks. 3. Proposed Technique This Technique is used to detect and prevent SQLIAs with runtime monitoring. The solution insights behind th e technique are that for each application, when the login page is redirected to our checking page, it was to detect and prevent SQL Injection attacks without stopping countenance accesses. Moreover, this technique proved to be efficient, imposing only a low overhead on the Web pplications. The contribution of this work is as follows A new automated technique for preventing SQLIAs where no code modification required, Webservice which has the functions of db_2_XMLGenrerator and XPATH_ Validator such that it is an XML query language to select specific parts of an XML document. XPATH is simply the ability to traverse leaf nodes from XML and obtain information. It is used for the temporary storage of sensitive datas from the database, nimble go for model is used to detect and prevent SQL Injection attacks. Service Detector model allow the evidence or legitimize user to access the web applications.The SQLIAs are captured by altered logical flow of the application. Innovative techniq ue (figure1) monitors dynamically generated queries with expeditious Guard model and Service Detector model at runtime and check them for compliance. If the Data Comparison violates the model then it represents potential SQLIAs and prevented from executing on the database. This proposed technique consists of two filtration models to prevent SQLIAS. 1) Active Guard filtration model 2) Service Detector filtration model. The steps are summarized and then describe them in more detail in following sections. a. Active Guard Filtration ModelActive Guard Filtration Model in application layer build a aptitude detector to detect and prevent the Susceptibility characters or Meta characters to prevent the malicious attacks from accessing the datas from database. b. Service Detector Filtration Model Service Detector Filtration Model in application layer validates user input from XPATH_Validator where the gauzy datas are stored from the Database at second 201 level filtration model. The user i nput fields compare with the data existed in XPATH_Validator if it is uniform then the Authenticated / decriminalise user is allowed to proceed. c. Web Service LayerWeb service builds two types of execution process that are DB_2_Xml generator and XPATH_ Validator. DB_2_Xml generator is used to create a separate temporary storage of Xml document from database where the Sensitive datas are stored in XPATH_ Validator, The user input field from the Service Detector compare with the data existed in XPATH_ Validator, if the datas are similar XPATH_ Validator send a flag with the count iterator value = 1 to the Service Detector by signifying the user data is valid. Procedures put to death in Active Guard feed stripQuotes(ByVal strWords) stripQuotes = Replace(strWords, , ) Return stripQuotesEnd Function Function killChars(ByVal strWords) thick arr1 As New ArrayList arr1. Add(select) arr1. Add() arr1. Add(drop) arr1. Add() arr1. Add(insert) arr1. Add(delete) arr1. Add(xp_) arr1. Add() p itch-dark i As Integer For i = 0 To arr1. see 1 strWords = Replace(strWords, arr1. Item(i), , , , CompareMethod. Text) Next Return strWords End Function IJCSNS International Journal of Computer Science and Network Security, VOL. 11 No. 1, January 2011 202 Figure 2 proposed Architecture Procedures Executed in Service Detector navi. Compile(/Main_Tag/ expositLoginId= & userName & and Password= & Password & ) _ domain Sub Db_2_XML() adapt=New SqlDataAdapter(select LoginId,Password from user_info, cn) Dim nodes As XPathNodeIterator = navi. Select(expr) Dim count2 As Integer = nodes. Count. ToString() Return count2 dst = New DataSet(Main_Tag) End Function adapt. Fill(dst, Details) dst. WriteXml(Server. MapPath(XML_DATAXML_D ATA. xml)) End Sub Procedures Executed in Web Service _ Public Function XPath_XML_ verification(ByVal userName As String, ByVal Password As Integer) As Integer Dim xpathdoc As New XPathDocument(Server. MapPath(XML_DATAX ML_DATA. xml)) Dim navi As XPathNavigator = x pathdoc. CreateNavigator() Dim expr As XPathExpression = . order hotspot This step performs a simple scanning of the application code to identify hotspots. Each hotspot will be verified with the Active Server to remove the susceptibility character the sample code (figure 2) states two hotspots with a single query execution. (In . NET based applications, interactions with the database occur through calls to specific methods in the System. Data. Sqlclient namespace, 1 such as Sqlcommand- . ExecuteReader (String)) the hotspot is instrumented with monitor code, which matches dynamically generated queries against query models. If a generated query is matched with Active Guard, then it is onsidered an attack. 3. 1 Comparison of Data at Runtime Monitoring When a Web application fails to properly sanitize the parameters, which are passed to, dynamically created SQL statements (even when using parameterization techniques) it is possible for an attacker to alter the construction of back-end SQL statements. IJCSNS International Journal of Computer Science and Network Security, VOL. 11 No. 1, January 2011 When an attacker is able to modify an SQL statement, the statement will execute with the same rights as the application user when using the SQL server to execute commands that interact with the operating system, the rocess will run with the same permissions as the component that executed the command (e. g. , database server, application server, or Web server), which is often highly privileged. Current technique (Figure 1) append with Active Guard, to validate the user input fields to detect the Meta character and prevent the malicious attacker. Transact-SQL statements will be prohibited directly from user input. For each hotspot, statically build a Susceptibility detector in Active Guard to check any malicious strings or characters append SQL tokens (SQL keywords and operators), delimiters, or string tokens to the legitimate command.Concurrently in Web service the DB_2_ Xml Generator generates a XML document from database and stored in X_PATH Validator. Service Detector receive the validated user input from Active Guard and send through the communications communications protocol max (Simple Object entrance money Protocol) to the web service from the web service the user input data compare with XML_Validator if it is identical the XML_Validator send a flag as a iterator count value = 1 to Service Detector through the SOAP protocol then the legitimate/valid user is Authenticated to access the web application, If the data mismatches the XML_Validator send a flag as a count alue = 0 to Service Detector through the SOAP protocol then the illegitimate/invalid user is not Authenticated to access the web application. In figure 3 In the existing technique query validation occur to validate a Authenticated user and the user directly access the database but in the current technique, there is no query validation . From the Active Guard the validated user inp ut fields compare with the Service Detector where the Sensitive data is stored, db_2_XML Generator is used to generate a XML file and initialize to the clan XPATH document the instance Navigator is used to search by using cursor in the selected XML document.With in the XPATH validator, Compile is a method which is used to match the element with the existing document. The navigator will be created in the xpathdocument using select method result will be redirected to the XPATH node iterator. The node iterator count value may be 1 or 0, If the flag value result in Service Detector as 1 then the user consider as Legitimate user and allowed to access the web application as the same the flag value result in Service Detector as 0 then the user consider as Malicious user and reject/ gaol from accessing the web application If the script builds an SQL query by concatenating hard-coded trings together with a string entered by the user, As long as injected SQL code is syntactically correct, ta mpering cannot be detected programmatically. String concatenation is the primary point of entry for script injection Therefore, 203 we Compare all user input carefully with Service Detector (Second filtration model). If the user input and Sensitive datas are identical then executes constructed SQL commands in the Application server. quick techniques directly allows accessing the database in database server after the Query validation. Web Service Oriented XPATH Authentication Technique does not allow directly to ccess database in database server. 4. EVALUATIONS The proposed technique is deployed and tried few trial runs on the web server. accede 1 SQLIAS Prevention Accuracy SQL Injection Types Unprotected protect 1. TAUTOLOGIES Not Prevented Prevented 2. PIGGY BACKED QUERIES Not Prevented Prevented 3. STORED PROCEDURE Not Prevented Prevented 4. alternate(a) ENCODING Not Prevented Prevented 5. UNION Not Prevented Prevented Table 2 capital punishment Time comparison for proposed t echnique Total Number of Entries in Database writ of execution Time in Millisecond vivacious Proposed Technique Technique one thousand 1640000 46000 2000 1420000 93000 3000 1040000 6000 4000 1210000 62000 5000 1670000 78000 6000 1390000 107000 The above given table 2 illustrate the execution time taken for the proposed technique with the existing technique. 4. 1 SQLIA Prevention Accuracy two the protected and unprotected web Applications are tested using different types of SQLIAs namely use of Tautologies, Union, Piggy-Backed Queries, Inserting additional SQL statements, Second-order SQL injection and various other SQLIA s. Table 1 shows that the proposed technique prevented all types of SQLIA s in all cases. The proposed technique is thus a secure and robust solution to defend against SQLIAsIJCSNS International Journal of Computer Science and Network Security, VOL. 11 No. 1, January 2011 204 4. 2 performance Time at Runtime Validation The runtime validation incurs some overhea d in terms of execution time at both the Web Service Oriented XPATH Authentication Technique and SQL-Query based Validation Technique. Taken a sample website ETransaction measured the extra computation time at the query validation, this delay has been amplified in the graph (figure 4 and figure5) to distinguish between the Time delays using bar chart shows that the data validation in XML_Validator performs better than query validation.In Query validation(figure5) the user input is generated as a query in script engine then it gets parsed in to separate tokens then the user input is compared with the statistical generated data if it is malicious generates error reporting. Web Service Oriented XPATH Authentication Technique (figure 4) states that user input is generated as a query in script engine then it gets parsed in to separate tokens, and send through the protocol SOAP to Susceptibility Detector, then the validated user data is sequentially send to Service Detector through the pr otocol SOAP then the user input is ompared with the sensitive data, which is temporarily stored in dataset. If it is malicious data, it will be prevented otherwise the legitimate data is allowed to access the Web application. 5. mop up SQL Injection Attacks attempts to modify the parameters of a Web-based application in order to alter the SQL statements that are parsed to retrieve data from the database. Any procedure that constructs SQL statements could potentially be vulnerable, as the diverse nature of SQL and the methods available for constructing it provide a riches of coding options. 1800000 Execution time in Milli Sec 1600000 1400000 1200000 000000 Proposed Technique Existing Technique 800000 600000 400000 200000 0 1000 2000 3000 4000 5000 6000 Total Number of Entries in Database Figure4 Execution Time comparison for proposed technique (data validation in X-path) with existing technique The primary form of SQL injection consists of direct insertion of code into parameters t hat are concatenated with SQL commands and executed. This technique is used to detect and prevent the SQLI flaw (Susceptibility characters & exploiting SQL commands) in Susceptibility Detector and prevent the Susceptibility attacker Web Service Oriented XPATH Authentication Technique hecks the user input with valid database which is stored separately in XPATH and do not affect database directly then the validated user input field is allowed to access the web application as well as used to improve the performance of the server side validation This proposed technique was able to suitably classify the attacks that performed on the applications without blocking legitimate accesses to the database (i. e. , the technique produced neither false positives nor false negatives). These results show that our technique represents a promising approach to countering SQLIAs and motivate further work in this irection References 1 William G. J. Halfond and Alessandro Orso , AMNESIA Analysis and Monit oring for Neutralizing SQLInjection Attacks, ASE05, November 711, 2005 2 William G. J. Hal fond and Alessandro Orso, A mixed bag of SQL injection attacks and countermeasures,proc IEEE intl Symp. dependable Software Engg. , Mar. 2006. IJCSNS International Journal of Computer Science and Network Security, VOL. 11 No. 1, January 2011 3 Muthuprasanna, Ke Wei, Suraj Kothari, Eliminating SQL Injection Attacks A TransparentDefenceMechanism, SQL Injection Attacks Prof. Jim whitenesshead CMPS 183. Spring 2006, May 17, 2006 4 William G. J. Hal fond, Alessandro Orso, WASP Protecting Web Applications Using Positive Tainting and Syntax-Aware Evaluation IEEE Software Engineering, VOL. 34, NO. 1January/February 2008 5 K. Beaver, Achieving Sarbanes-Oxley compliance for Web applications, http//www. spidynamics. com/support/whitepapers/, 2003 6 C. Anley, Advanced SQL Injection In SQL Server Applications, White paper, Next multiplication Security Software Ltd. , 2002. 7 W. G. J. Halfond and A. Ors o, Combining Static Analysis and Runtime Monitoring to forestall SQL Injection Attacks, 3rd International Workshop on Dynamic Analysis, 2005, pp. 7 8 Z. Su and G. Wassermann, The Essence of Command Injection Attacks in Web Applications, 33rd ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, 2006, pp. 372-382. 9 G. Wassermann and Z. Su. An Analysis Framework for Security in Web Applications. In proceeding of the FSE Workshop on Specification and Verification of componentBased Systems (SAVCBS 2004), pages 7078, 2004. 10 P. Finnigan, SQL Injection and Oracle Parts 1 & 2, Technical Report, Security Focus, November 2002. http//securityfocus. com/infocus/1644 11 F. Bouma, Stored Procedures are Bad, Okay, Technical report,Asp. Net Weblogs, November 2003. http//weblogs. asp. net/fbouma/archive/2003/11/18/38178. as px. 12 E. M. Fayo, Advanced SQL Injection in Oracle Databases, Technical report, Argeniss Information Security, low-spirited Hat Briefings, Black Hat USA, 2 005. 13 C. A. Mackay, SQL Injection Attacks and Some Tips on How to Prevent them, Technical report, The Code Project, January 2005. http//www. codeproject. com/cs/database/ qlInjectionAttacks. asp. 14 S. McDonald. SQL Injection Modes of attack, defense, and why it matters. White paper, GovernmentSecurity. org, April 2002. http//www. governmentsecurity. rg/articles/SQLInjectionM odesofAttackDefenceandWhyItMatters. php 15 S. Labs. SQL Injection. White paper, SPI Dynamics, Inc. ,2002. http//www. spidynamics. com/assets/documents/Whitepaper SQLInjection. pdf. 16 V. B. Livshits and M. S. Lam. Finding Security Errors in Java Programs with Static Analysis. In Proceedings of the 14th Usenix Security Symposium, pages 271286, Aug. 2005. 17 F. Valeur and D. Mutz and G. Vigna A Learning-Based Approach to the Detection of SQL Attacks, In Proceedings of the congregation on Detection of Intrusions and Malware Vulnerability Assessment (DIMVA), July 2005. 18 Kals, S. Kirda, E. , Kruegel, C. , and J ovanovic, N. 2006. SecuBat a web vulnerability scanner. In Proceedings of the 205 15th International Conference on World Wide Web. WWW 06. ACM Press, pp. 247-256. 19 Sql injection HSC Guides Web App Security Written by Ethical Hacker sunday, 17 February 2008. http//sqlinjections. blogspot. com/2009/04/sql-injection-hscguides-web-app. html. Prof. E. Ramaraj is presently working as a Technology Advisor, Madurai Kamaraj University, Madurai, Tamilnadu, India on lien from Director, computer center of attention at Alagappa university, Karaikudi. He has 22 years teaching experience and 8 years esearch experience. He has presented research papers in more than 50 national and international conferences and published more than 55 papers in national and international journals. His research areas include Data mining, software engineering, database and communicate security. B. Indrani received the B. Sc. degree in Computer Science, in 2002 the M. Sc. degree in Computer Science and Information Technology, in 2004. She had completed M. Phil. in Computer Science. She worked as a Research Assistant in Smart and Secure Environment Lab under IIT, Madras. Her current research interests include Database Security.
Eyewitness: Life Essay
In the movie Eyewitness Life, I had galore(postnominal) existent observations. First, I noted that cockroaches bottom of the inning survive very low temperatures up until -40c. This has been a very efficient method for their natural selection. They atomic proceeds 18 among the few creatures that charter survived from the prehistoric era. During the change of times and periods much(prenominal) as the ice age, approxi colleaguely prehistoric creatures engender become extinct. It is this conciliateation of the cockroaches that has wholeowed them to withstand change and be around until today. Second, it showed that humans need to eat as much as they weigh every 50 days.This shows the balance of intake and output with regard to the usage of forage we eat for survival. It shows that an adequate amount of nutrition is consequential to maintain hotshots self. Its amazing how every 50 days, a 70kg man actually should be taking in 70 kg worth of food for thought which is a lar ge quantity, much much than wed actually notice day by day. Third, primitive sustenance nookieful multiply very fast at break cut speeds. The entailment of this is yet another(prenominal)(prenominal) method of survival. In the wild, there argon many a(prenominal) another(prenominal) predators which can devour the young.Being equal to quickly multiply allows disposition to continually maintenance species alive and in good numbers condescension the dangers that abound. Fourth, early giraffes may pee-pee started with short necks but as they stretched their necks for food they passed on the genes to next generation. This shows us how each specie can adapt to its environment. This allowed giraffes to adapt in order to provide for its needs. Through time, the lengthening of the neck of a giraffe is proof of an animals capability to gear up to its environment for survival. Fifth, to a greater extent or less male birds catch fish to attract females.The laws of attractor be i ndeed as real in temper as they atomic number 18 among us men. Sixth, oxygen isnt al itinerarys a demand for invigoration. Bacteria fix in deep oceans do not posit oxygen. This shows us diversity in nature. Although we humans use oxygen, other creatures are capable of utilizing the other gases for their survival. Those that dont be possessed of access to oxygen, very(prenominal) the bacteria, can adapt and utilize other mode. Seventh, when a live quick study is shredded it will replace itself exactly the same way. Once to a owing(p)er extent we see how unitary can adapt to its environment and survive. This method of transition is how the sponge values itself from extinction.The same goes for starfish and other similar creatures. They can re-grow a lost appendage or part to replace what may have been damaged by a predator. Eighth, tortoises on the Galapagos Island have a crack in their neck, a mutated trait that is passed on to adapt to their environment. Once more, s imilar the giraffe, nature shows how a specie can adapt through time. Ninth, birds are incredible breathing machines. Some can sing without taking another breath. This is an interesting fact. It shows a similarity of birds to us humans, where professional opera singers can mimic this bird standardised quality and sing for extended periods on one breath.Lastly, snails run low 0. 0013 km per hour. Indeed, they are among the slowest creatures on earth. Hence, nature for adaptation has provided them with a shell for protection, as although speed may not be utilize for defense, at least the hard covering may pose some resistance in order to survive. Eyewitness shoetrees In the second movie, the initial fact I knowledgeable was that trees once cover 4/5 of Earths land mass. Secondly, I too noted that trees however cover half(prenominal) of planet area today. This tells me two things.First, trees apparently through time have been an essential part of wildlife and the balance of n ature, as since they covered 4/5th of the earth in the lead, they were very much integrated in nature. Second, it shows me how much we have already lost. To have plainly a half left shows how much more should be done to preserve these trees before even more are destroyed. The third fact is learned is that the oak tree offers habitat for many living things and is one of 30 cat valium kinds of trees. Again, this further shows that trees are essential for animals and other wildlife, and the preservation of them is important to protect many aspects of nature.Frogs, salamanders, insects and many more depend on these trees and protecting these creatures means protecting their trees. Fourth, trees can grow almost anywhere, but occasional nature is inhospitable such as in the North and South poles. This shows us that apart from these obscure places, our protection of the forest may not only consist of preventing destruction, but of re pass watering forests as well. Industry over the ol d age has destroyed much of them. As these trees are very capable of increase in almost anywhere, then there is even greater reasonableness to set forth and begin the amends of these lost forests.Fifth, I learned that from aspirin to the latest cancer drugs, we find treatment from trees. This is a major contribution of trees to our own survival. As these trees show much promise to the gentlemans gentleman of medicine, then all the more people must be do aware that they must be preserved. For each time some are taken for study, then new ones should be planted. How is the world to progress if we keep taking and taking, and one day there is no more? another(prenominal) fact I learned was that it takes 4000 mature trees are needed to build a ship.Given the way industry today has taken over, this shows that thousands of trees have been taken to fill our harbors for cargo and trade. The question is how many of them were actually replaced? It enlightens us regarding the sheer amount of trees that are being taken. In light of their many uses, such as the medicinal use, then much care should be implemented in maintaining a balance amid harvest of these trees and restoration of them. Imagine this, the seventh fact I learned was that one tree provides full year oxygen for 8 people. This means that the 4000 trees taken for one ship is oxygen for 32000 people lost.These trees very much provide for us so much, and such, much more concern should be placed on their survival. Eighth fact I learned was that tropical trees grow all year, and for each year, trees grow by bonnie leaveing rings around their trunk. They add up a new coat each year. I found this interesting as it shows how nature found a way to chronicle for age just the way we do. Ninth, trees are homes for variety of animals. For example, leopards store their target on trees. Again, not only do trees provide a way of life for the small creatures like frogs and snakes, but for the larger animals as well.A whole environment and diverse balance of life revolves around one tree, from oxygen production, to shelter, to food, and all these are deprived from creatures by their loss. Thus, by destroying trees, we are contributing to the loss of nature itself. The know fact I learned was an interesting one about the giant sequoia. This apparently is the biggest tree and can grow up until 34-storeys tall. In a tree so great and so large, imagine how much it can provide to all life around it. Amazing. Eyewitness Mammals I learned many things from this movie as well. The first fact I learned was that elephants never stop growing.Apparently, they can live up until 80 years, however in the wild, only until 30 years. I found it interesting that the elephants can actually live as long as we do. Also interesting was how much shorter they live in the wild, precisely 50 years shorter. This shows us the role of care and resources to life. In the wild, they have to provide food for themselves and in th e event of a drought and such, when food is scarce, survival time is shorter. Secondly, in the wild, they are exposed to the elements, such as wind, heat and rain, which bear wear and tear on them too decreasing life.Of course, as an additional factor, they are targets as objective for carnivores and this also can decrease their life span. When in care, they are exempt from many of these, thus they live longer lives. Id say the same for us humans, and any other creature, who can expect longer lives when in good care and nurturing environment. The second fact I learned was that cockamamie are only mammals that can truly fly. They have great piloting skills, can see pray without using their eyes, and have enough thievery to attack their prey without being heard.This primarily shows that bats are in fact not birds, and belong to our group of species the mammals. Its interesting how they have managed to adapt by garnering the ability to approach in stealth. This ensures them adequa te food resource needed to survive. It also helps with their habitat, as their flight skills allow them to navigate in the dark caves where the dwell. Third, polar bear have black pare and white fur. This was interesting as it shows camouflage. Polar bears live in flash-frozen regions. Their white fur allows them to blend in the surroundings to aid in the hunt for food. Fourth, a duck that lay eggs is a mammal.As ducks are birds, there are some mammals that may look like a duck because they possess a similar foot tissue or beak, such as a platypus. Fifth, some anteaters eat 30000 ants per day. This was another interesting fact as 30000 ants a day, would mean 210000 ants a week, and millions more a month. Sixth, rabbits communicate with tail talk. Communication is one similarity between us and animals only in different form. It interesting to see how just like we do, animals have learned to coordinate by other forms of communication. As whales can use their sonar, rabbits use the ir tails.Seventh fact is that camels are able to detect water more than few days apart. These creatures live in the deserts where water is scarce. This ability is an amazing adaptation as it allows them to survival resources in the harshest conditions. Their hump is also another adaptation is it stores energy and plunk needed in the event that water and food are miles away through the desert. Eighth, a dominant male seal can mate 100 times in one season. This is a survival method. By having the capability to do so, one males can impregnate more than a hundred females thus ensuring a lot of newborn seals to increase their number by next season.It keeps them in survival despite being prey to the polar bears and killer whales. Ninth, a mouse is only pregnant 6 weeks and a cat 9 weeks. The short gestation period allows populate for multiple births a year, against ensuring survival of a species through regular reproduction. The last fact was that if a hedgehog get offs down from heig ht, it bounces. This was so interesting, as it apparently has a ball like quality. This helps it survive a fall as it covering allows the bounce to reduce the pressure of impact, and helping it survive.
Subscribe to:
Posts (Atom)