The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 5  ■ Bypassing Client-Side Controls



Download 5,76 Mb.
Pdf ko'rish
bet179/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   175   176   177   178   179   180   181   182   ...   875
Bog'liq
3794 1008 4334

Chapter 5 



Bypassing Client-Side Controls



101

70779c05.qxd:WileyRed  9/16/07  5:14 PM  Page 101




When this is observed, you may reasonably infer that when the form is sub-

mitted, the server-side application will decrypt or deobfuscate the opaque string

and perform some processing on its plaintext value. This further processing may

be vulnerable to any kind of bug; however, in order to probe for and exploit this,

you will first need to wrap up your payload in the appropriate way.

HACK STEPS

Faced with opaque data being transmitted via the client, there are a several

possible avenues of attack:



If you know the value of the plaintext behind the opaque string, you can



attempt to decipher the obfuscation algorithm being employed.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   175   176   177   178   179   180   181   182   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish