command can be used on Sun’s Solaris.
■
Test every page of the application by inserting a single unique string (such
as
traversaltest
) into each submitted parameter (including all cookies,
query string fields, and
POST
data items). Target only one parameter at a
time, and use the automated techniques described in Chapter 13 to speed
up the process.
■
Set a filter in your file system monitoring tool to identify all file system
events that contain your test string.
■
If any events are identified where your test string has been used as or
incorporated into a file or directory name, test each instance (as described
next) to determine whether it is vulnerable to path traversal attacks.
Do'stlaringiz bilan baham: |