The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 4  ■ Mapping the Application



Download 5,76 Mb.
Pdf ko'rish
bet141/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   137   138   139   140   141   142   143   144   ...   875
Bog'liq
3794 1008 4334

Chapter 4 



Mapping the Application



75

70779c04.qxd:WileyRed  9/14/07  3:12 PM  Page 75




HACK STEPS

There are several useful options available when running Nikto:



If you believe that the server is using a nonstandard location for interest-



ing content that Nikto checks for (for example 

/cgi/cgi-bin



instead of

/cgi-bin


) you can specify this alternate location using the option 

–root


/cgi/

. For the specific case of CGI directories, these can also be speci-

fied using the option 

–Cgidirs


.



If the site uses a custom “file not found” page that does not return the



HTTP 404 status code, you can specify a particular string that identifies

this page by using the 

-404


option.



Be aware that Nikto does not perform any intelligent verification of



potential issues and so is prone to report false positives. Always check

any results returned by Nikto manually.

Application Pages vs. Functional Paths

The enumeration techniques described so far have been implicitly driven by

one particular picture of how web application content may be conceptualized

and catalogued. This picture is inherited from the pre-application days of the

World Wide Web, in which web servers functioned as repositories of static

information, retrieved using URLs that were effectively filenames. To publish

some web content, an author simply generated a bunch of HTML files and

copied these into the relevant directory on a web server. When users followed

hyperlinks, they navigated around the set of files created by the author,

requesting each file via its name within the directory tree residing on the

server.

Although the evolution of web applications has fundamentally changed the

experience of interacting with the Web, the picture just described is still applic-

able to the majority of web application content and functionality. Individual

functions are typically accessed via a unique URL, which is usually the name

of the server-side script that implements the function. The parameters to the

request (residing in either the URL query string or the body of a 

POST


request)

do not tell the application what function to perform — they tell it what infor-

mation to use when performing it. In this context, the methodology of con-

structing a URL-based map can be effective in cataloging the functionality of

the application.

In some applications, however, the picture based on application “pages” is

inappropriate. While it may be logically possible to shoehorn any application’s

structure into this form of representation, there are many cases in which a 




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   137   138   139   140   141   142   143   144   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish