The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet112/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   108   109   110   111   112   113   114   115   ...   875
Bog'liq
3794 1008 4334

Mapping the Application

C H A P T E R

4

70779c04.qxd:WileyRed  9/14/07  3:12 PM  Page 61




Enumerating Content and Functionality

In a typical application, the majority of the content and functionality can be

identified via manual browsing. The basic approach is to walk through the

application starting from the main initial page, following every link and navi-

gating through all multistage functions (such as user registration or password

resetting). If the application contains a “site map,” this can provide a useful

starting point for enumerating content.

However, to perform a rigorous inspection of the enumerated content, and

to obtain a comprehensive record of everything identified, it is necessary to

employ some more advanced techniques than simple browsing.



Web Spidering

Various tools exist which perform automated spidering of web sites. These

tools work by requesting a web page, parsing it for links to other content,

and then requesting these, continuing recursively until no new content is

discovered.

Building on this basic function, web application spiders attempt to achieve

a higher level of coverage by also parsing HTML forms and submitting these

back to the application using various preset or random values. This can enable

them to walk through multistage functionality, and to follow forms-based nav-

igation (e.g., where drop-down lists are used as content menus). Some tools

also perform some parsing of client-side JavaScript to extract URLs pointing to

further content. The following free tools all do a decent job of enumerating

application content and functionality (see Chapter 19 for a detailed analysis of

their capabilities):

■■

Paros


■■

Burp Spider (part of Burp Suite)

■■

WebScarab



Figure 4-1 shows the results of using Burp Spider to map part of an application.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   108   109   110   111   112   113   114   115   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish