- Hands-On Application Penetration Testing with Burp Suite
- Carlos A. Lozano Dhruv Shah Riyaz Ahemed Walikar
- 133字
- 2021-07-02 12:16:38
Client-end code analysis
Based on the type of test, we can perform code analysis too. For applications that are hosted as a part of white box testing, the entire code will be available to the tester and he can use custom tools to perform an entire code review and find vulnerabilities based on the code logic. Let's say it is a black box and code analysis needs to be done. Given a black box scenario, the only code analysis that would happen is the client-end code and the JavaScript library references. Based on the analysis, a tester can bypass certain validation logic implemented by these scripts and enable us to perform certain attacks.
In the next chapter, we will be talking in detail about how we can bypass client-side logic by code manipulation.
推薦閱讀
- unidbg逆向工程:原理與實(shí)踐
- 科技安全:戰(zhàn)略實(shí)踐與展望
- Kali Linux Social Engineering
- API安全實(shí)戰(zhàn)
- 大型互聯(lián)網(wǎng)企業(yè)安全架構(gòu)
- 計(jì)算機(jī)使用安全與防護(hù)
- 安全實(shí)戰(zhàn)之滲透測試
- Enterprise Cloud Security and Governance
- Mastering Kali Linux for Advanced Penetration Testing
- 數(shù)據(jù)安全實(shí)踐指南
- 軟件安全保障體系架構(gòu)
- 隱私計(jì)算:推進(jìn)數(shù)據(jù)“可用不可見”的關(guān)鍵技術(shù)
- Hands-On Artificial Intelligence for Cybersecurity
- 網(wǎng)絡(luò)空間安全導(dǎo)論
- Mastering Malware Analysis