-
Book Overview & Buying
-
Table Of Contents
The Web Application Hacker's Handbook
By :
The best way to learn about logic flaws is not by theorizing, but by becoming acquainted with some actual examples. Although individual instances of logic flaws differ hugely, they share many common themes, and they demonstrate the kinds of mistakes that human developers will always be prone to making. Hence, insights gathered from studying a sample of logic flaws should help you uncover new flaws in entirely different situations.
The authors have found instances of the “encryption oracle” flaw within many different types of applications. They have used it in numerous attacks, from decrypting domain credentials in printing software to breaking cloud computing. The following is a classic example of the flaw found in a software sales site.
The application implemented a “remember me” function whereby a user could avoid logging in to the application on each visit by allowing the application...
Change the font size
Change margin width
Change background colour