tools. However, there are many instances in which
an application may expect
that ordinary users cannot view or modify URL parameters. For example:
■■
Where embedded images are loaded using URLs containing parameters.
■■
Where URLs containing parameters are used to load the contents of a
frame.
■■
Where a form uses the
POST
method and its target URL contains preset
parameters.
■■
Where an application uses pop-up windows or other techniques to con-
ceal the browser location bar.
Of course, in any such case the values of any URL parameters can be modi-
fied as previously using an intercepting proxy.
Do'stlaringiz bilan baham: