The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


The most obvious vulnerabilities of this kind will often be detected during the



Download 5,76 Mb.
Pdf ko'rish
bet626/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   622   623   624   625   626   627   628   629   ...   875
Bog'liq
3794 1008 4334

The most obvious vulnerabilities of this kind will often be detected during the

user-acceptance testing that normally occurs before an application is launched.

However, more subtle manifestations of the problem may remain, particularly

when hidden parameters are being manipulated.

HACK STEPS

The first step in attempting to beat a business limit is to understand what

characters are accepted within the relevant input which you control.



Try entering negative values and see if these are accepted by the applica-



tion and processed in the way that you would expect.



You may need to perform several steps in order to engineer a change in



the application’s state that can be exploited for a useful purpose. For

example, several transfers between accounts may be required until a


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   622   623   624   625   626   627   628   629   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish