**Security Performance Analysis Of Photography Service System**

**Nur Khairani Kamarudin<sup>1</sup>, Farah Shazwani Ismail<sup>2</sup>, Mahfudzah Othman<sup>3</sup>,** **Nurul Hidayah Ahmad Zukri<sup>4</sup>,**

**Mohd Faris Mohd Fuzi<sup>4</sup>**

*<sup>12345</sup>Faculty of Computer and Mathematical Sciences, Universiti Teknologi MARA, Perlis Branch, Malaysia*

*Corresponding author: <nurkhairani@perlis.uitm.edu.my>*

**ABSTRACT**

*Photography business become more popular and trending among the most of people who likes photography. Photography Service System was developed to help photography companies to deliver photos and videos to their customers. The use of the system have its advantages such as easiness of accessing data and also make users share the data faster. The purpose of the system was developed to ease the daily works and can be used frequently by photography companies as a method to send photos and videos to their customers. A penetration testing was conducted in order to test the security performance by conducting four security attacks which were Denial of Service (DoS), SQL injection, Cross Site Scripting, and sniffing password. The purpose of these attacks were conducted is to testing and finding the vulnerabilities of the system because the system deals with the customers’ privacy data which is the photos and the videos owned by the customers. This is crucial to secure a system where the first step taken as a prevention to introduce the system to the public, vulnerability assessments was performed to determine the weaknesses of the system. Scanning and vulnerability assessment are done using tools which is Vega Scanning Tool, Wireshark, and Low Orbit Ion Cannon (LOIC). All results are collected and have been analyze. As a summary of the result, it shows that the system are vulnerable to DoS attack, SQL injection attack, cross site scripting and also password sniffing.*

*Keywords— Denial of Service (DoS), SQL injection, Cross Site Scripting, sniffing password*

# **Introduction**

Photography business and services have become more popular in these days. The methods for the photography company to deliver their customers’ photo are hardcopy and softcopy. Customers often request to get the softcopy of the photos as soon as they can get them so that they can post the pictures on their social media such as Facebook, Instagram, and Twitter. A photography company usually delivers the softcopy of the photos to the customers through WhatsApp, Telegram, or cloud storage such as Google Drive and Dropbox. Cloud computing attracts more attention from business companies (Aishwarya & Malliga,2014). Photography Service System will be the best choice of delivering the softcopy of the customers’ photos since the quality of the photos or files uploaded to the system will not be reduced and can deliver the photos quickly. The service system enables users to outsource their data to a server and access data remotely over the Internet (Anu, 2017). The system allows users to store and maintain data on a remote server that is managed by Cloud Service Provider (CSP) like Yahoo and Google (Dinis & Serrao, 2014). Users can process their data on their computers, and use the data on other devices such as mobile phones (Ghafarian, 2017). By using the system to deliver the photos to the customers, the customers can easily receive the photos since they can use their computers or mobile phones to receive the photos. This research project is purposely done to test the system to determine the security flaws and vulnerabilities in this system. Security is one of the efficiency standards where it is the main indicator and guideline of the performance level. Security is essential to the system because it protects the system from threats. Security in the system is a highly sensitive and important factor because it deals with confidential data in the system (Goyal & Goyal, 2017). Every system should provide a strong security protection and privacy to protect the data of its customers who are using the system. The system should avoid security threats. For example, Denial of Service (DoS) attack, SQL injection, Cross Site Scripting (XSS), and sniffing password. These attacks are attempted to prevent a system from performing its normal functions.

# **Methodology**

## **Sotware Description**

The software used for this research project was VMWare Workstation, LOIC – Low ORBIT Ion Cannon, Wireshark, and Vega.

1\) VMWare Workstation

VMWare Workstation is a virtual machine software that is used for x86 and x86-64 computers to run multiple operating systems over a single physical host computer. Each virtual machine can run a single instance of any operating system (Microsoft Linux, etc) simultaneously (Nagpure & Kurkure, 2017).

2\) LOIC – Low Orbit Ion Cannon

LOIC is an open-source network stress testing and denial-of-service attack application, written in C. It was initially developed by Praetox Technologies but was later released into the public domain and now is hosted on several open source platform (Dinis, B., & Serrao, C.,2014).

3\) Wireshark

Wireshark is an open-source packet analyzer. It is used for network troubleshooting, analysis, software and communication protocol development, and education. It is originally named Ethereal, the project was renamed Wireshark in May 2006 due to trademark issues (Gupta, Jain, Saini, & Gupta, 2016).

4\) Vega Scanning tool

Vega is a free and open-source web security scanner and web security testing platform to test the security of web applications. Vega can help find and validate SQL Injection, Cross Site Scripting (XSS), inadvertently disclosed sensitive information, and other vulnerabilities.

## **Hardware Description**

Laptop used for the research project and many specification of laptop that was used is summarized which are the model of laptop is Asus. The processor is Intel Core i5-4200U, the RAM of a laptop used is 8.00 GB, and system type of the laptop used is 64-bit operating system, x-64-based processor.

## **Testbed Architecture**

![diagram](108-1-277-2-2-20190710_media/media/image1.jpeg)

> **Figure** **1** Testbed Architecture

The web server of photography service system’s IP address is 192.168.43.118 while the attacker’s IP address is 192.168.43.95. The attacker will act as white hat hacker who wants to test the photography service system performance based on Denial of Service (DoS) attack, SQL injection attack, Cross Site Scripting (XSS) attack, and sniffing password attack.

# **result and findings**

In this research project, a pilot study was conducted to ensure all equipment were working properly. Processes that have been done during pilot study including installation all the required software and tools to conduct the experiment in this research project. A web server which is photography service system was running on VMWare Workstation.

During the development of the testbed, the web server of photography service system’s IP address is 192.168.43.118 while the attacker’s IP address is 192.168.43.95. The attacker will act as white hat hacker which want to test the photography service system performance based on Denial of Service (DoS) attack, SQL injection attack, Cross Site Scripting (XSS) attack, and sniffing password attack.

## **Performance analysis based response time without DoS attack**

Thus, packet captured at 677, the response time recorded was 0.025447000 seconds. This is the time when the web server response to the client faster after doing any activities in the system without DoS attack. After completing the pilot study, the experiment was executed and recorded. The data collected were recorded in the table.

In Table 1 shows the result for the testing on response time without implementing DoS attack. From the result, it can be concluded that the photography system performance is going well and not vulnerable.

Table 1 Result response time without DoS

> ![](108-1-277-2-2-20190710_media/media/image2.png)

As shown in the graph in Figure 2, depict the measurement response time graph without dos attack.

> ![](108-1-277-2-2-20190710_media/media/image3.png)

Figure 2 Response time graph without dos

The first test criteria tested was doing the analysis of finding the response time before implementing a DoS attack towards the system to test the performance of the web application. The result shows the result on response time without implementing DoS attack yet using Wireshark. From the result, the response time for each packet captured for 5 times without launch DoS attack took less than 1 second while doing any activities in the system. All the activities doing in the system such as key-in the data of their clients, update the latest information, and delete the data, all of this kind activities show that the expected outcome which was all give the positive impact where the response time took not too long time to be recorded.

## **Performance analysis based on response time with DoS attack**

The result on response time with implementing DoS attack using Wireshark. From the result, the response time for each packet captured for 5 times took more than 1 second while doing any activities in the system. It is achieved by launching a series of data packets very rapidly at a target computer system until it becomes too slow to be usable or brought down entirely. All the activities doing in the system give the negative impact where the response time took too long time to be recorded because of while running the DoS attack, the system performed very slow until hard for Wireshark to capture all the packets. The target system becomes slow as its central processing unit (CPU) attempts to handle the requests and serve responses.

Next, from the experiment testing, there are data that have been successfully captured as shown in Table 2, packet captured at 79240, the response time recorded was 16.524329000 seconds. This is the time when the web server response to the client slower after doing any activities in the system with DoS attack.

Table 2 Result response time with DoS attack

![](108-1-277-2-2-20190710_media/media/image4.png)

As shown in the graph in Figure 3 is the measurement of response time graph with implementing DoS attack.

![image\_2018-11-30\_23-19-48](108-1-277-2-2-20190710_media/media/image5.png)

Figure 3 Response time graph with dos attack

The second test criteria tested was doing the analysis of finding the response time after implementing a DoS attack towards the system to test the performance of the web application. The data recorded after implementing the DoS attack which there is one of the security testings was performed to determine the security flaws and vulnerabilities in this system. A DoS attack was automated attempt using DoS attack tool which is LOIC (Low Orbit Ion Cannon) to overload a target system with a large volume of requests to render it unavailable for use. From Figure 3, shows the result of the response time graph after this experiment was conducted.

## **SQL injection** 

SQL injection is type of security exploit where the SQL queries are executed without proper validation of user inputs, to access or alter the data. The common this attack can be happen which malicious user inputs some crafted data and application uses that data to build a SQL statement. SQL injection vulnerability occurs when untrusted data flowing from user input with inadequate validation which is input validation where analyze the data against a predefined pattern, sanitizing, cleaning, and filtering input data is used for constructing SQL queries.

Figure 4 Result for scanning vulnerabilities

![](108-1-277-2-2-20190710_media/media/image6.png)

After scanning the vulnerabilities of the system have been done, the third test criteria tested was doing the SQL injection attack. SQL injection will be chosen because it can be categorised as an attack that is classified to gain access which matches the objective of this project. After inject with this code based on Figure 4, this experiment found that the following code is SQL injection code successfully to breach illegally into the system.

![](108-1-277-2-2-20190710_media/media/image7.png)

Figure 5 SQL injection code

Figure 4 shows that show the two examples of SQL injection code to bypass authentication using the following queries in the user input which are:

  - > ‘ OR ‘1’ = ‘1

  - > ‘or 1=1 –

## **Cross Site Scripting**

After done scanning the vulnerabilities of the system, the fourth test criteria tested was doing the XSS attack. Cross Site Scripting attacks can be carried out using HTML, JavaScript, and other client-side languages. This attack also possible have the ability to gather the information and important data from account hijacking, changing of user settings, cookie theft/poisoning, or false advertising. This attack also can lead to a breach of security when customer details are stolen or manipulated. This attack involves three parties where the attacker, a client, and the web site.

![](108-1-277-2-2-20190710_media/media/image8.png)

Figure 6 XSS code

Password sniffing attack is the attack when someone or attacker want the user's password by sniffing to bypass the authentication of the system. So, for this experiment the tester wants to testing and checking the system by sniffing password using Wireshark tool to observe what outcome after the testing have been done. The purpose is to know either the username and password that input by user were encrypt or not. Furthermore, website that are vulnerable usually transmit username and password as clear-text and plain-text.

![](108-1-277-2-2-20190710_media/media/image9.png)

Figure 7 Password Sniffing

Figure 7 show the result of sniffing password attack was successfully identified. From this system, the tester can view the ‘customer\_id=1024’ and ‘customer\_password=0134657904’ with plain-text without encryption. The tester find out the attacker can use the id and password to gain access on the system. This is show that the encryption is very important to implement in the system. To sum up, the system has many flaws and vulnerabilities which need improvement in security because from username and password that can easily sniffed by the attacker, this help them to bypass the authentication that can harm others information and identity.

# **conclusion**

In conclusion, from scanning and vulnerability assessment that have been made, it shows the photography service system many weaknesses was found. In exploitation, the photography service system can be breached and exploited via SQL injection, Cross site scripting and password sniffing. This shows that, this photography system need to improve its security performance before being introduce and used by the customer. In addition, this paper helps other web developer in evaluating their web system security performance by using software and hardware used. .

# **References**

Aishwarya, R., & Malliga, S. (2014). Intrusion detection system- An efficient way to thwart against Dos/DDos attack in the cloud environment. *2014 International Conference on Recent Trends in Information Technology, ICRTIT 2014*.

Anu, P. (2017). A survey on sniffing attacks on computer networks.

Dinis, B., & Serrao, C. (2014). External footprinting security assessments security assessments, 313–318.

Ghafarian, A. (2017). A Hybrid Method for Detection and Prevention of SQL Injection Attacks, (July), 833–838. https://doi.org/10.1109/SAI.2017.8252192

Goyal, P., & Goyal, A. (2017). Comparative Study of two Most Popular Packet Sniffing Tools- Tcpdump and Wireshark, 77–81. https://doi.org/10.1109/CICN.2017.19

Gupta, N., Jain, A., Saini, P., & Gupta, V. (2016). DDoS attack algorithm using ICMP flood, 4082–4084.

Nagpure, S., & Kurkure, S. (2017). Vulnerability Assessment and Penetration Testing of Web Application. *2017 International Conference on Computing, Communication, Control and Automation (ICCUBEA)*, 1–6. https://doi.org/10.1109/ICCUBEA.2017.8463920
