The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 6  ■ Attacking Authentication



Download 5,76 Mb.
Pdf ko'rish
bet308/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   304   305   306   307   308   309   310   311   ...   875
Bog'liq
3794 1008 4334

Chapter 6 



Attacking Authentication



173

70779c06.qxd:WileyRed  9/14/07  3:13 PM  Page 173




5. An application incorporates an anti-phishing mechanism into its login

functionality. During registration, each user selects a specific image

from a large bank of memorable images presented to them by the appli-

cation. The login function involves the following steps:

(a) The user enters their username and date of birth.

(b) If these details are correct, the application displays to the user their

chosen image; otherwise, a random image is displayed.

(c) The user verifies that the correct image is displayed, and if so, enters

their password.

The idea behind the anti-phishing mechanism is that it enables the user

to confirm that they are dealing with the authentic application, and not

a clone, because only the real application knows the correct image to

display to the user.

What vulnerability does the anti-phishing mechanism introduce into

the login function? Is the mechanism effective in preventing phishing?


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   304   305   306   307   308   309   310   311   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish