The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet482/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   478   479   480   481   482   483   484   485   ...   875
Bog'liq
3794 1008 4334

Exploiting Defective Filters

It is very common for applications to seek to defend themselves against SQL

injection by escaping any single quotation marks that appear within string-

based user input (and rejecting any that appear within numeric input). As you

have seen, two single quotation marks together are an escape sequence that

represents one literal single quote, which the database will interpret as data

within a quoted string rather than the closing string terminator. Many devel-

opers reason, therefore, that by doubling up any single quotation marks

within user-supplied input, they will prevent any SQL injection attacks from

occurring.

In addition to doubling up quotation marks, some applications perform

other operations in an effort to sanitize potentially malicious input. In this sit-

uation, it may be possible to exploit the ordering of these steps to bypass the

filter, as described in Chapter 2.

Recall the vulnerable login example. Suppose that the application doubles

up any single quotation marks contained in user input, and also then imposes

a length limit on the data, truncating it to 20 characters. Supplying the 

username


admin’-- 


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   478   479   480   481   482   483   484   485   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish