relation: https://khub.utp.edu.my/scholars/4161/ title: SQL injections attack and session hijacking on e-learning systems creator: Chung, S.K. creator: Yee, O.C. creator: Singh, M.M. creator: Hassan, R. description: E-learning enables acquisition of knowledge and information through technologies such as computers, smartphones, tablets and wide area networks. The existence of e-learning does contribute in the field of education field such as in the university because its improve the education quality and distributing and sharing of teaching material efficiently. However, due to the open-network in which e-learning tools resides, it is prone to various security attacks. In this paper, we will classify e-learning technology security based attacks into classification via active and passive attacks. Next, two major attacks which is the SQL injection attack and session hijacking is explored in-depth. Case study for each attack to investigate the vulnerabilities in e-learning system and mechanism of solutions to tackle this attack is also presented. An evaluation of the proposed solutions against the X.800 security architecture is done at the end of the study. © 2014 IEEE. publisher: Institute of Electrical and Electronics Engineers Inc. date: 2014 type: Conference or Workshop Item type: PeerReviewed identifier: Chung, S.K. and Yee, O.C. and Singh, M.M. and Hassan, R. (2014) SQL injections attack and session hijacking on e-learning systems. In: UNSPECIFIED. relation: https://www.scopus.com/inward/record.uri?eid=2-s2.0-84925945841&doi=10.1109%2fI4CT.2014.6914201&partnerID=40&md5=a9cea5ca381e6a655bd7a997f5b920a3 relation: 10.1109/I4CT.2014.6914201 identifier: 10.1109/I4CT.2014.6914201