Chuyển đến nội dung chính

Bài đăng

Bài Hướng Dẫn Mutillidae : Lesson 15 - Man-in-the-Middle, Persistent Covert Cross Site Scripting Injection #2

{ Man-in-the-Middle, Persistent Covert Cross Site Scripting Injection #2 } Section 0. Background Information What is Mutillidae? OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast. What is a Man-In-The-Middle attack? The man-in-the-middle attack take on many forms.  The most common form is active network eavesdropping in which the attacker is able to gain authentication credentials (Username, Password, SESSIONID, Cookies Information, etc).   What is a Reflective Cross Site Scripting? The non-persistent (or reflected) cross-site scripting vulnerability is by far the most common type. These holes show up when the data provided by a web client, most commonly in HTTP query parameters or in HTML form submissions, is used immediately by server-side scripts to parse and display a page of results for and to that user, without properly sanitizing the request. ...