The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet753/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   749   750   751   752   753   754   755   756   ...   875
Bog'liq
3794 1008 4334

Preventing Frame Injection

There are two available mitigations to frame injection vulnerabilities:

■■

If there is no requirement for the application’s different frames to inter-



communicate, remove frame names altogether and make them anony-

mous. However, because intercommunication is normally required, this

option is usually not feasible.

■■

Use named frames but make them unique to each session and unpre-



dictable. One possible option is to append the user’s session token to

each base frame name such as 

main_display

.

Request Forgery

This category of attack (also known as session riding) is closely related to ses-

sion hijacking attacks, in which an attacker captures a user’s session token and

so is able to use the application “as” that user. With request forgery, however,

the attacker need never actually know the victim’s session token. Rather, the

attacker exploits the normal behavior of web browsers in order to hijack a


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   749   750   751   752   753   754   755   756   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish