The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Completely Unprotected Functionality



Download 5,76 Mb.
Pdf ko'rish
bet390/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   386   387   388   389   390   391   392   393   ...   875
Bog'liq
3794 1008 4334

Completely Unprotected Functionality

In many cases of broken access controls, sensitive functionality and resources

can be accessed by anyone who knows the relevant URL. For example, there

are many applications in which anyone who visits a specific URL is able to

make full use of its administrative functions:

https://wahh-app.com/admin/

In this situation, the application typically enforces access control only to the

following extent: users who have logged in as administrators see a link to this

URL on their user interface, while other users do not. This cosmetic difference

is the only mechanism in place to “protect” the sensitive functionality from

unauthorized use.

Sometimes, the URL that grants access to powerful functions may be less

easy to guess, and may even be quite cryptic, for example:

https://wahh-app.com/menus/secure/ff457/DoAdminMenu2.jsp

Here, access to administrative functions is protected by the assumption that

an attacker will not know or discover this URL. The application is harder for a

complete outsider to compromise, because they are less likely to guess the

URL by which they can do so.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   386   387   388   389   390   391   392   393   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish