If you find that either item is returned as the other, or simply as
test
, then
you can be confident that your input is being inserted into an XML-based
message.
■
If the HTTP request contains several parameters which may be being
placed into a SOAP message, try inserting the opening comment charac-
ter
into one parameter and the closing comment character
!-->
into another parameter. Then, switch these around (because you have no
way of knowing which order the parameters appear in). This can have the
effect of commenting out a portion of the server’s SOAP message, which
may cause a change in the application’s logic, or result in a different
error condition which may divulge information.
Do'stlaringiz bilan baham: |