官术网_书友最值得收藏!

Client-end code analysis

Based on the type of test, we can perform code analysis too. For applications that are hosted as a part of white box testing, the entire code will be available to the tester and he can use custom tools to perform an entire code review and find vulnerabilities based on the code logic. Let's say it is a black box and code analysis needs to be done. Given a black box scenario, the only code analysis that would happen is the client-end code and the JavaScript library references. Based on the analysis, a tester can bypass certain validation logic implemented by these scripts and enable us to perform certain attacks.

In the next chapter, we will be talking in detail about how we can bypass client-side logic by code manipulation.

主站蜘蛛池模板: 鞍山市| 丰原市| 始兴县| 高青县| 固原市| 历史| 靖江市| 金川县| 桂阳县| 高州市| 周宁县| 庆云县| 阳城县| 黄大仙区| 吉林省| 明水县| 阳曲县| 台南市| 江油市| 庆元县| 孝义市| 兴化市| 志丹县| 长汀县| 宝清县| 会宁县| 乌苏市| 盐源县| 界首市| 杂多县| 连城县| 百色市| 横峰县| 德阳市| 武强县| 卢湾区| 承德市| 大宁县| 蒙城县| 饶河县| 温州市|