The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


party code components that are being used within the application. You



Download 5,76 Mb.
Pdf ko'rish
bet846/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   842   843   844   845   846   847   848   849   ...   875
Bog'liq
3794 1008 4334


party code components that are being used within the application. You

can review the documentation for these components to understand their

intended behavior and assumptions. You can also create your own local

implementation and test this to understand the ways in which it handles

unexpected input and potentially identify vulnerabilities.

■■

The call stack includes the names of the proprietary code components



being used to process the request. The naming scheme for these and the

interrelationships between them may allow you to infer details about

the internal structure and functionality of the application.

■■

The stack trace often includes line numbers. As with the simple script



error messages described previously, these may enable you to probe and

understand the internal logic of individual application components.

■■

The error message often includes additional information about the



application and the environment in which it is running. In the preced-

ing example, you can determine the exact version of the ASP.NET plat-

form being used. This enables you to investigate the platform for

known or new vulnerabilities, anomalous behavior, common configura-

tion errors, and so on.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   842   843   844   845   846   847   848   849   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish