The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet239/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   235   236   237   238   239   240   241   242   ...   875
Bog'liq
3794 1008 4334

136

Chapter 6 



Attacking Authentication

70779c06.qxd:WileyRed  9/14/07  3:13 PM  Page 136



even to an amateur attacker who manually enters some common usernames

and passwords into their browser. Values frequently encountered even in pro-

duction systems include:

■■

test



■■

testuser


■■

admin


■■

administrator

■■

demo


■■

demouser


■■

password


■■

password1

■■

password123



■■

qwerty


■■

test123


■■

letmein


■■

[organization’s name]

In this situation, any serious attacker will use automated techniques to

attempt to guess passwords, based on lengthy lists of common values. Given

today’s bandwidth and processing capabilities, it is possible to make thou-

sands of login attempts per minute from a standard PC and DSL connection.

Even the most robust passwords will be eventually broken in this scenario.

Various techniques and tools for using automation in this way are described

in detail in Chapter 13. Figure 6-2 demonstrates a successful password guess-

ing attack against a single account using Burp Intruder. The successful login

attempt can be clearly distinguished by the difference in the HTTP response

code, the response length, and the absence of the “login incorrect” message.



N OT E


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   235   236   237   238   239   240   241   242   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish