官术网_书友最值得收藏!

Client-end code analysis

Based on the type of test, we can perform code analysis too. For applications that are hosted as a part of white box testing, the entire code will be available to the tester and he can use custom tools to perform an entire code review and find vulnerabilities based on the code logic. Let's say it is a black box and code analysis needs to be done. Given a black box scenario, the only code analysis that would happen is the client-end code and the JavaScript library references. Based on the analysis, a tester can bypass certain validation logic implemented by these scripts and enable us to perform certain attacks.

In the next chapter, we will be talking in detail about how we can bypass client-side logic by code manipulation.

主站蜘蛛池模板: 西青区| 平潭县| 武山县| 杂多县| 嘉义县| 伊通| 宜兰县| 甘洛县| 湛江市| 武义县| 连云港市| 建平县| 教育| 呈贡县| 汝阳县| 永嘉县| 盐山县| 徐闻县| 松阳县| 揭西县| 新巴尔虎右旗| 云和县| 卢氏县| 镶黄旗| 武夷山市| 收藏| 榆社县| 巢湖市| 博乐市| 青冈县| 盐津县| 龙胜| 林甸县| 香河县| 全南县| 凌云县| 黄大仙区| 鄂托克前旗| 永胜县| 蕲春县| 邹城市|