The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 4  ■ Mapping the Application



Download 5,76 Mb.
Pdf ko'rish
bet143/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   139   140   141   142   143   144   145   146   ...   875
Bog'liq
3794 1008 4334

Chapter 4 



Mapping the Application



77

70779c04.qxd:WileyRed  9/14/07  3:12 PM  Page 77




Representing an application’s functionality in this way is often more useful

even in cases where the usual picture based on application pages can be

applied without any problems. The logical relationships and dependencies

between different functions may not correspond to the directory structure

used within URLs. It is these logical relationships that are of most interest to

you, both in understanding the core functionality of the application, and in

formulating possible attacks against it. By identifying these, you can better

understand the expectations and assumptions of the application’s developers

when implementing the functions, and attempt to find ways of violating these

assumptions, causing unexpected behavior within the application.

In applications where functions are identified using a request parameter,

rather than the URL, this has implications for the enumeration of application

content. In the previous example, the content discovery exercises described so

far are unlikely to uncover any hidden content. Those techniques need to be

adapted to the mechanisms actually used by the application for accessing

functionality.



HACK STEPS




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   139   140   141   142   143   144   145   146   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish