The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


If an application explicitly liberalizes its cookies’ scope to a parent



Download 5,76 Mb.
Pdf ko'rish
bet370/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   366   367   368   369   370   371   372   373   ...   875
Bog'liq
3794 1008 4334

If an application explicitly liberalizes its cookies’ scope to a parent

domain or parent directory, then it may be leaving itself vulnerable to

attacks via other web applications.



If an application sets its cookies’ domain scope to its own domain name



(or does not specify a domain attribute), then it may still be exposed to

applications or functionality accessible via subdomains.



If an application specifies its cookies’ path scope without using a trailing



slash, then it might be exposed to other applications residing at paths

containing a prefix that matches the specified scope.

Identify all of the possible domain names and paths that will receive the

cookies issued by the application. Establish whether any other web application

or functionality is accessible via these domain names or paths that you may be

able to leverage to obtain the cookies issued to users of the target application.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   366   367   368   369   370   371   372   373   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish