The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet673/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   669   670   671   672   673   674   675   676   ...   875
Bog'liq
3794 1008 4334

Injecting Trojan Functionality

This attack goes beyond virtual defacement and injects actual working func-

tionality into the vulnerable application, designed to deceive end users into

performing some undesirable action, such as entering sensitive data that is

then transmitted to the attacker.

An obvious attack involving injected functionality is to present users with a

Trojan login form that submits their credentials to a server controlled by the

attacker. If skillfully executed, the attack may also seamlessly log the user in to

the real application, so that they do not detect any anomaly in their experience.

The attacker is then free to use the victim’s credentials for his own purposes.

This type of payload lends itself well to a phishing-style attack, in which users

are fed a crafted URL within the actual authentic application and advised that

they will need to log in as normal to access it.

Another obvious attack is to ask users to enter their credit card details, usu-

ally with the inducement of some attractive offer. For example, Figure 12-8

shows a proof-of-concept attack created by Jim Ley, exploiting a reflected XSS

vulnerability found in Google in 2004.


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   669   670   671   672   673   674   675   676   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish