(at least a few hundred). Gather these tokens in as quick succession as
possible, to minimize the loss of tokens issued to other users and reduce
the influence of any time dependency. The following screenshot shows
Burp Intruder being used to make large numbers of requests and log the
returned cookies, which can then be exported for further analysis.
■
If a commercial session management mechanism is in use and/or you
have local access to the application, you can obtain indefinitely large
sequences of session tokens in controlled conditions.
■
Attempt to identify any patterns within your sample of cookies. There are
various tools (including the testing suite WebScarab) that will attempt to
perform some automated analysis on a sample of cookies. This kind of
Do'stlaringiz bilan baham: |