The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet672/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   668   669   670   671   672   673   674   675   ...   875
Bog'liq
3794 1008 4334

Virtual Defacement

This attack involves injecting malicious data into a page of a web application

to feed misleading information to users of the application. It may simply

involve injecting HTML mark-up into the site, or it may use scripts (sometimes

hosted on an external server) to inject elaborate content and navigation into

the site. This kind of attack is known as virtual defacement because the actual

content hosted on the target’s web server is not modified — the defacement is

Chapter 12 



Attacking Other Users



391

70779c12.qxd:WileyRed  9/14/07  3:14 PM  Page 391




generated solely because of the way the application processes and renders

user-supplied input.

In addition to frivolous mischief, this kind of attack could be used for seri-

ous criminal purposes. A professionally crafted defacement, delivered to the

right recipients in a convincing manner, could be picked up by the news media

and have real-world effects on people’s behavior, stock prices, and so on, to the

financial gain of the attacker, as illustrated in Figure 12-7.

Figure 12-7: A virtual defacement attack exploiting an XSS flaw


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   668   669   670   671   672   673   674   675   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish