The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet235/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   231   232   233   234   235   236   237   238   ...   875
Bog'liq
3794 1008 4334

134

Chapter 6 



Attacking Authentication

70779c06.qxd:WileyRed  9/14/07  3:13 PM  Page 134



Some web applications employ client-side SSL certificates or cryptographic

mechanisms implemented within smartcards. Because of the overhead of

administering and distributing these items, they are typically used only in

security-critical contexts where an application’s user base is small.

The HTTP-based authentication mechanisms (basic, digest, and Windows-

integrated) are rarely used on the Internet, and are much more commonly

encountered in intranet environments where an organization’s internal users

gain access to corporate applications by supplying their normal network or

domain credentials, which are processed by the application via one of these

technologies.

Third-party authentication services such as Microsoft Passport are occasion-

ally encountered, but at the present time have not been adopted on any signif-

icant scale.

Most of the vulnerabilities and attacks that arise in relation to authentication

can be applied to any of the technologies mentioned. Because of its over-

whelming dominance, we will describe each specific vulnerability and attack

in the context of HTML forms-based authentication, and where relevant will

point towards any specific differences and attack methodologies that are rele-

vant to the other available technologies.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   231   232   233   234   235   236   237   238   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish