The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Do not fall into the trap of examining actions that the application per-



Download 5,76 Mb.
Pdf ko'rish
bet356/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   352   353   354   355   356   357   358   359   ...   875
Bog'liq
3794 1008 4334

Do not fall into the trap of examining actions that the application per-

forms on the client-side token (such as cookie invalidation via a new

Set-Cookie



instruction, client-side script, or an expiration time

attribute). In terms of session termination, nothing much depends upon

what happens to the token within the client browser. Rather, investigate

whether session expiration is implemented on the server side:



Log in to the application to obtain a valid session token.



Wait for a period without using this token, and then submit a request

for a protected page (e.g., “my details”) using the token.



If the page is displayed as normal, then the token is still active.



Use trial and error to determine how long any session expiration time-


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   352   353   354   355   356   357   358   359   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish