The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 7  ■ Attacking Session Management



Download 5,76 Mb.
Pdf ko'rish
bet327/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   323   324   325   326   327   328   329   330   ...   875
Bog'liq
3794 1008 4334

Chapter 7 



Attacking Session Management



183

70779c07.qxd:WileyRed  9/14/07  3:13 PM  Page 183




Concealed Sequences

It is common to encounter session tokens that cannot be trivially predicted

when analyzed in their raw form but that contain sequences that reveal them-

selves when the tokens are suitably decoded or unpacked.

Consider the following series of values, which form one component of a

structured session token:

lwjVJA

Ls3Ajg


xpKr+A

XleXYg


9hyCzA

jeFuNg


JaZZoA

No immediate pattern is discernible; however, a cursory inspection indi-

cates that the tokens may contain Base64-encoded data — in addition to the

mixed-case alphabetical and numeric characters, there is a + character, which

is also valid in a Base64-encoded string. Running the tokens through a Base64

decoder reveals the following:

--Õ$

.ÍÀŽ


Æ’«ø

^W-b


ö‚Ì

?án6


%¦Y 

These strings appear to be gibberish and also contain nonprinting charac-

ters. This normally indicates that you are dealing with binary data rather than

ASCII text. Rendering the decoded data as hexadecimal numbers gives you:

9708D524

2ECDC08E


C692ABF8

5E579762


F61C82CC

8DE16E36


25A659A0

There is still no visible pattern. However, if you subtract each number from

the previous one, you arrive at the following:

FF97C4EB6A

97C4EB6A

FF97C4EB6A




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   323   324   325   326   327   328   329   330   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish