The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Information page displays a user’s personal details together with his



Download 5,76 Mb.
Pdf ko'rish
bet409/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   405   406   407   408   409   410   411   412   ...   875
Bog'liq
3794 1008 4334

Information page displays a user’s personal details together with his

username and password. While the password is typically masked on-screen,

it is nevertheless transmitted in full to the browser. Here, you can often

quickly iterate through the full range of account identifiers to harvest the

login credentials of all users, including administrators. The following example

shows Burp Intruder being used to carry out a successful attack of this kind.

T I P

When you have detected an access control vulnerability, an immediate

attack to follow up with is to attempt to escalate your privileges further by

compromising a user account with administrative privileges. There are various

tricks you can use in trying to locate an administrative account. Using an 

access control flaw like the one illustrated, you may harvest hundreds of user

credentials and not relish the task of logging in manually as every user until an


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   405   406   407   408   409   410   411   412   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish