The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


product and submit this in its place



Download 5,76 Mb.
Pdf ko'rish
bet181/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   177   178   179   180   181   182   183   184   ...   875
Bog'liq
3794 1008 4334

product and submit this in its place.



If all else fails, you can attempt to attack the server-side logic that will



decrypt or deobfuscate the opaque string, by submitting malformed vari-

ations of it — for example, containing overlong values, different character

sets, and the like.

The ASP.NET ViewState

One commonly encountered mechanism for transmitting opaque data via the

client is the ASP.NET ViewState. This is a hidden field that is created by default

in all ASP.NET web applications, and contains serialized information about

the state of the current page. The ASP.NET platform employs the ViewState to

enhance server performance — it enables the server to preserve elements

within the user interface across successive requests without needing to main-

tain all of the relevant state information on the server side. For example, the

server may populate a drop-down list on the basis of parameters submitted by

the user. When the user makes subsequent requests, the browser does not

 submit the contents of the list back to the server. However, the browser does

submit the hidden ViewState field, which contains a serialized form of the list.

The server deserializes the ViewState and recreates the same list that is pre-

sented back to the user again.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   177   178   179   180   181   182   183   184   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish