Local Privacy Attacks
Many users access web applications from a shared environment in which an
attacker may have direct access to the same computer as the user. This gives
rise to a range of attacks to which insecure applications may leave their users
vulnerable. There are several areas in which this kind of attack may arise.
Persistent Cookies
Some applications store sensitive data in a persistent cookie, which most
browsers save on the local file system.
HACK STEPS
■
Review all of the cookies identified during your application mapping
exercises (see Chapter 4). If any
Set-cookie
Do'stlaringiz bilan baham: