Hacker Professional Ebook part 251

Ebook giới thiệu các công cụ và đồ nghề cần thiết cho việc Hack-Security. Ebook gồm có 1177 bài viết trong 28 chủ đề chính Phần 25: 10 part gồm Google Hack. | The screenshot below shows the ipconfig command being run on the database using the xpcmdshell stored procedure We have achieved remote command execution on an internal server which is not accessible from the outside In fact with this same example we have also achieved privilege escalation since we are accessing the database using system administrator credentials. A quick check by running would show us what privileges we get The above screenshot verifies that we indeed have administrative privileges that of the NT_AUTHORITY SYSTEM user. Concluding thoughts One-way hacks illustrate the fact that firewalls are not enough to protect a web application. A tight firewall can make things difficult for an attacker but not keep the attacker entirely away. In fact with tools like the file uploader the web based command prompt and the web based SQL command prompt it is just as easy to attack a web application and the underlying network with a tight firewall in place. SSL makes things even worse 8 from the point of view of securing the application. Many people think that SSL prevents such attacks. It does not. SSL is used only to encrypt the data between the web browser and the web server to prevent eavesdropping. SSL provides no security to the web application or the underlying network. All one-way hacks can be easily adapted to SSL using libraries such as OpenSSL. References 1. Web Hacking Attacks and Defense - Saumil Shah Shreeraj Shah Stuart McClure Addison Wesley 2002 2. Inside-Out Attacks - Patrick Heim Saumil Shah 1999 3. Forms in HTML documents - multipart form-data - from http 4. RFC 1867 - Form-based File Upload in HTML 5. Microsoft IIS In-Process Table Privilege Elevation Vulnerability 6. Linux Ptrace Setuid Exec Vulnerability 7. Securiteam - Ptrace Exploit Code 8. SSL - a false sense of security by Chris Prosise and Saumil Shah Hết phần cuối ngại dịch quá do đang vội nhưng có lẽ cũng ko ảnh hưởng gì lắm. Chúc cả nha vui vẻ pip .

Không thể tạo bản xem trước, hãy bấm tải xuống
TÀI LIỆU LIÊN QUAN
5    176    1
5    255    1
5    106    0
5    121    1
6    103    1
6    107    1
6    121    1
6    103    0
6    140    0
TÀI LIỆU MỚI ĐĂNG
16    82    1    17-06-2024
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.