The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


each directory or path known to exist within the application. Use Burp



Download 5,76 Mb.
Pdf ko'rish
bet126/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   122   123   124   125   126   127   128   129   ...   875
Bog'liq
3794 1008 4334

each directory or path known to exist within the application. Use Burp

Intruder or a custom script, together with wordlists of common files and

directories, to quickly generate large numbers of requests. If you have

identified a particular way in which the application handles requests for

invalid resources (e.g., a customized “file not found” page), configure

Intruder or your script to highlight these results so they can be ignored.



Capture the responses received from the server, and manually review



these to identify valid resources.



Perform the exercise recursively as new content is discovered.



Inference from Published Content

Most applications employ some kind of naming scheme for their content and

functionality. By inferring from the resources already identified within the

application, it is possible to fine-tune your automated enumeration exercise to

increase the likelihood of discovering further hidden content.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   122   123   124   125   126   127   128   129   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish