The easiest and most effective way to test the effectiveness of an applica-
tion’s access controls is to access the application using different accounts, and
determine whether resources and functionality that can be accessed legiti-
mately by one account can be accessed illegitimately by another.
HACK STEPS
■
Do'stlaringiz bilan baham: