The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet329/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   325   326   327   328   329   330   331   332   ...   875
Bog'liq
3794 1008 4334

Time Dependency 

Some web servers and applications employ algorithms for generating session

tokens that use the time of generation as an input to the token’s value. If insuf-

ficient other entropy is incorporated into the algorithm, then you may be able

to predict other users’ tokens. Although any given sequence of tokens on its

own may appear to be completely random, the same sequence coupled with

information about the time at which each token was generated may contain a

discernible pattern. In a busy application, with large numbers of sessions

being created per second, a scripted attack may succeed in identifying large

numbers of other users’ tokens.

When testing the web application of an online retailer, the authors encoun-

tered the following sequence of session tokens:

3124538-1172764258718

3124539-1172764259062

3124540-1172764259281

3124541-1172764259734

3124542-1172764260046

3124543-1172764260156

3124544-1172764260296

3124545-1172764260421

3124546-1172764260812

3124547-1172764260890

Each token is clearly composed of two separate numeric components. The

first number follows a simple incrementing sequence and is trivial to predict.

The second number is increasing by a varying amount each time. Calculating

the differences between its value in each successive token reveals the following:

344

219


453

312


110


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   325   326   327   328   329   330   331   332   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish