The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet734/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   730   731   732   733   734   735   736   737   ...   875
Bog'liq
3794 1008 4334

428

Chapter 12 



Attacking Other Users

70779c12.qxd:WileyRed  9/14/07  3:14 PM  Page 428



Finding and Exploiting Redirection Vulnerabilities

The first step in locating redirection vulnerabilities is to identify every instance

within the application where a redirect occurs. There are several ways in which

an application can cause the user’s browser to redirect to a different URL:

■■

An HTTP redirect uses a message with a 3xx status code and a Location



header specifying the target of the redirect. For example:

HTTP/1.1 302 Object moved

Location: https://wahh-app.com/showDetails.php?uid=19821

■■

The HTTP 



Refresh

header can be used to reload a page with an arbi-

trary URL after a fixed interval, which may be zero to trigger an imme-

diate redirect. For example:

HTTP/1.1 200 OK

Refresh: 0; url=https://wahh-app.com/showDetails.php?uid=19821

■■

The HTML 



tag can be used to replicate the behavior of any

HTTP header and can, therefore, be used for redirection. For example:

HTTP/1.1 200 OK

Content-Length: 125





”0;url=https://wahh-app.com/showDetails.php?uid=19821”>





■■

Various APIs exist within JavaScript that can be used to redirect the



browser to an arbitrary URL. For example:

HTTP/1.1 200 OK

Content-Length: 120












Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   730   731   732   733   734   735   736   737   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish