The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet193/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   189   190   191   192   193   194   195   196   ...   875
Bog'liq
3794 1008 4334

108

Chapter 5 



Bypassing Client-Side Controls

70779c05.qxd:WileyRed  9/16/07  5:14 PM  Page 108



logic to intercept an attempted form submission, perform customized validation

checks on the user’s input, and decide whether to accept that input accordingly.

In the above example, the validation is extremely simple and checks whether the

data entered in the amount field is an integer.

Client-side controls of this kind are usually trivial to circumvent, and it is

normally sufficient to disable JavaScript within the browser. If this is done, the

onsubmit

attribute is ignored, and the form is submitted without any custom

validation.

However, disabling JavaScript altogether may break the application if it

depends upon client-side scripting for its normal operation (such as construct-

ing parts of the user interface). A neater approach is to enter a benign value

into the input field in the browser, and then intercept the validated submission

with your proxy and modify the data to your desired value.

Alternatively, you can intercept the server’s response that contains the

JavaScript validation routine and modify the script to neutralize its effect — in

the previous example, by changing the 

ValidateForm

function to return true in

every case.



HACK STEPS




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   189   190   191   192   193   194   195   196   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish