The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 12  ■ Attacking Other Users



Download 5,76 Mb.
Pdf ko'rish
bet649/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   645   646   647   648   649   650   651   652   ...   875
Bog'liq
3794 1008 4334

Chapter 12 



Attacking Other Users



377

70779c12.qxd:WileyRed  9/14/07  3:14 PM  Page 377




For example, consider the following URL, which returns the error message

shown in Figure 12-1:

https://wahh-app.com/error.php?message=Sorry%2c+an+error+occurred

Figure 12-1: A dynamically generated error message

Looking at the HTML source for the returned page, we can see that the

application is simply copying the value of the 

message


parameter in the URL

and inserting this into the error page template at the appropriate place:


Sorry, an error occurred.


This behavior of taking user-supplied input and inserting it into the HTML

of the server’s response is one of the signatures of XSS vulnerabilities, and if no

filtering or sanitization is being performed, then the application is certainly

vulnerable. Let’s see how.

The following URL has been crafted to replace the error message with a

piece of JavaScript that generates a pop-up dialog:

https://wahh-app.com/error.php?message=

Requesting this URL generates an HTML page that contains the following in

place of the original message:





And sure enough, when the page is rendered within the user’s browser, the

pop-up message appears, as shown in Figure 12-2.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   645   646   647   648   649   650   651   652   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish