The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


that protects users from malicious cloned sites



Download 5,76 Mb.
Pdf ko'rish
bet658/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   654   655   656   657   658   659   660   661   ...   875
Bog'liq
3794 1008 4334

that protects users from malicious cloned sites.

■■

Most banks won’t take responsibility if their customers visit a cloned



web site. They cannot disassociate themselves so easily if customers

are attacked via an XSS flaw in their own application.

■■

As you will see, there are ways of delivering XSS attacks that do not



use phishing-style techniques.

Stored XSS Vulnerabilities

A different category of XSS vulnerability is often referred to as stored cross-site

scripting. This version arises when data submitted by one user is stored within

the application (typically in a back-end database) and then displayed to other

users without being filtered or sanitized appropriately.

Stored XSS vulnerabilities are common in applications that support interac-

tion between end users, or where administrative staff access user records and

data within the same application. For example, consider an auction applica-

tion that allows buyers to post questions about specific items, and sellers to


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   654   655   656   657   658   659   660   661   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish