eprintid: 4161 rev_number: 2 eprint_status: archive userid: 1 dir: disk0/00/00/41/61 datestamp: 2023-11-09 16:15:49 lastmod: 2023-11-09 16:15:49 status_changed: 2023-11-09 15:57:48 type: conference_item metadata_visibility: show creators_name: Chung, S.K. creators_name: Yee, O.C. creators_name: Singh, M.M. creators_name: Hassan, R. title: SQL injections attack and session hijacking on e-learning systems ispublished: pub keywords: E-learning; Network architecture; Network security; Wide area networks, E-learning technology; Education quality; Security; Security Architecture; Session Hijacking; SQL injection; Sql injection attacks; Teaching materials, Learning systems note: cited By 3; Conference of 1st International Conference on Computer, Communications, and Control Technology, I4CT 2014 ; Conference Date: 2 September 2014 Through 4 September 2014 abstract: E-learning enables acquisition of knowledge and information through technologies such as computers, smartphones, tablets and wide area networks. The existence of e-learning does contribute in the field of education field such as in the university because its improve the education quality and distributing and sharing of teaching material efficiently. However, due to the open-network in which e-learning tools resides, it is prone to various security attacks. In this paper, we will classify e-learning technology security based attacks into classification via active and passive attacks. Next, two major attacks which is the SQL injection attack and session hijacking is explored in-depth. Case study for each attack to investigate the vulnerabilities in e-learning system and mechanism of solutions to tackle this attack is also presented. An evaluation of the proposed solutions against the X.800 security architecture is done at the end of the study. © 2014 IEEE. date: 2014 publisher: Institute of Electrical and Electronics Engineers Inc. official_url: https://www.scopus.com/inward/record.uri?eid=2-s2.0-84925945841&doi=10.1109%2fI4CT.2014.6914201&partnerID=40&md5=a9cea5ca381e6a655bd7a997f5b920a3 id_number: 10.1109/I4CT.2014.6914201 full_text_status: none publication: I4CT 2014 - 1st International Conference on Computer, Communications, and Control Technology, Proceedings pagerange: 338-342 refereed: TRUE isbn: 9781479945559 citation: Chung, S.K. and Yee, O.C. and Singh, M.M. and Hassan, R. (2014) SQL injections attack and session hijacking on e-learning systems. In: UNSPECIFIED.