The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


The example script shown works on Internet Explorer. A slightly more



Download 5,76 Mb.
Pdf ko'rish
bet791/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   787   788   789   790   791   792   793   794   ...   875
Bog'liq
3794 1008 4334

The example script shown works on Internet Explorer. A slightly more

complicated script could be created that worked on all common browsers.

The MySpace worm, which exploited a stored XSS vulnerability, employed

Ajax techniques, and provides a useful example of the kind of complex opera-

tions that can be carried out using this technology. The steps performed by the

worm’s payload included the following:

1. Parse the source code of the current page to extract the ID of the

MySpace user who is viewing it.

2. If the current page was issued by the domain 

profile.myspace.com

,

switch the location to 



www.myspace.com

with the same relative URL.

(The 

profile.myspace.com



domain can only be used to view profiles,

while the 

www.myspace.com

domain can also be used to add new friends

and perform other tasks. Because 

XMLHttpRequest

can only be used to

make requests to the same domain that issued it, it is necessary to

switch domain before issuing requests to add friends.)

3. Parse the current page to extract the worm’s own source code, and

URL-encode it.

4. Make a 

GET

request to the user’s Add Friend page to extract the per-



page token that it contains.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   787   788   789   790   791   792   793   794   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish