The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


whether this uncovers or gives access to any additional functionality than



Download 5,76 Mb.
Pdf ko'rish
bet406/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   402   403   404   405   406   407   408   409   ...   875
Bog'liq
3794 1008 4334

whether this uncovers or gives access to any additional functionality than

your user context has normal access to.



Test whether the application uses the 

Referer

header as the basis for

making access control decisions. For key application functions that you

are authorized to access, try removing or modifying the 

Referer


header

and determine whether your request is still successful. If not, the appli-

cation may be trusting the 

Referer


header in an unsafe way.



Review all client-side HTML and scripts to find references to hidden func-



tionality or functionality that can be manipulated on the client side, such

as script-based user interfaces.

Once all accessible functionality has been enumerated, it is necessary to test

whether per-user segregation of access to resources is being correctly enforced.

In every instance where the application grants users access to a subset of a

wider range of resources of the same type (such as documents, orders, emails,

and personal details), there may be opportunities for one user to gain unau-

thorized access to other resources.

HACK STEPS




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   402   403   404   405   406   407   408   409   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish