The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


as in the following example, indicated by the presence of the



Download 5,76 Mb.
Pdf ko'rish
bet751/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   747   748   749   750   751   752   753   754   ...   875
Bog'liq
3794 1008 4334

as in the following example, indicated by the presence of the 

name


attribute in the tag that creates each frame:



frameborder=”yes” title=”Top menu”>



frameborder=”yes” title=”Left menu”>



frameborder=”yes” title=”Main display”>





If the frameset uses named frames, but the names appear to be highly



cryptic or random, access the application several times from different

browsers, and review whether the frame names change. If they do so,

and there is no way for an attacker to predict the names of other users’

frames, then the application is probably not vulnerable. 

Exploiting Frame Injection

If the application is vulnerable to frame injection, then an attacker can exploit

this using the following steps:

1. The attacker creates an innocuous-looking web site containing a script

that wakes up every 10 seconds and attempts to overwrite the contents

of the frame named 

main_display

. The new content is hosted on the

attacker’s site and contains Trojan functionality that looks identical to

the normal 

wahh-app.com

content, but transmits any entered data to the

attacker.

2. The attacker either waits for 

wahh-app.com

users to browse to his

innocuous site, or uses some proactive means of inducing them to do

so, such as sending emails, buying banner ads, and so on.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   747   748   749   750   751   752   753   754   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish