-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
Advanced Penetration Testing
By :
In this chapter, we look at delivering payloads by exploiting vulnerabilities in client-side software such as web browsers, their plugins, and other desktop code. New vulnerabilities are discovered and patched in applications every day and, as a consequence, there is little point in learning to attack specific bugs here, as these will have been long addressed before this book goes to print. That being said, there are the “usual suspects”—technologies in which serious bugs have been discovered on a seemingly weekly basis over the course of their long lives and as such are illustrative and interesting to explore.
The worst offender is Adobe Flash. Its almost universal presence combined with a long history of terrible security means that it is a staple of exploitation kits, ransomware, and drive-by-downloads. There is no secure way to deploy this horror story of a plugin—disable or remove...
Change the font size
Change margin width
Change background colour