The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet316/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   312   313   314   315   316   317   318   319   ...   875
Bog'liq
3794 1008 4334

178

Chapter 7 



Attacking Session Management

70779c07.qxd:WileyRed  9/14/07  3:13 PM  Page 178



browser, using HTTP headers, and not via application-specific code

contained within any individual page. Once a user has entered his 

credentials into a browser dialog, the browser effectively resubmits

these credentials (or reperforms any required handshake) with every

subsequent request to the same server. This is the equivalent to an

application that uses HTML forms-based authentication and places a

login form on every application page, requiring users to reauthenticate

themselves with every action they perform. Hence, when HTTP-based

authentication is used, it is possible for an application to re-identify the

user across multiple requests without using sessions. However, HTTP

authentication is rarely used on Internet-based applications of any com-

plexity, and the other very versatile benefits that fully fledged session

mechanisms offer mean that virtually all web applications do in fact

employ them.

■■


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   312   313   314   315   316   317   318   319   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish