You can test for this type of vulnerability without knowing exactly what
length limit is being imposed by submitting in turn two long strings of the
following form:
‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘ etc.
a’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘’‘ etc.
and determining whether an error occurs. Any truncation of escaped input will
either occur after an even number or an odd number of characters. Whichever
possibility is the case, one of the preceding strings will result in an odd number
Do'stlaringiz bilan baham: |