官术网_书友最值得收藏!

Client-end code analysis

Based on the type of test, we can perform code analysis too. For applications that are hosted as a part of white box testing, the entire code will be available to the tester and he can use custom tools to perform an entire code review and find vulnerabilities based on the code logic. Let's say it is a black box and code analysis needs to be done. Given a black box scenario, the only code analysis that would happen is the client-end code and the JavaScript library references. Based on the analysis, a tester can bypass certain validation logic implemented by these scripts and enable us to perform certain attacks.

In the next chapter, we will be talking in detail about how we can bypass client-side logic by code manipulation.

主站蜘蛛池模板: 永德县| 昭平县| 晋江市| 新安县| 本溪| 郓城县| 高邑县| 德州市| 保定市| 广饶县| 江北区| 图们市| 那坡县| 当阳市| 宁南县| 托里县| 天气| 万宁市| 朝阳区| 沙湾县| 北流市| 亚东县| 天峻县| 清苑县| 汽车| 西贡区| 壤塘县| 鹤庆县| 金川县| 汶上县| 九江市| 内乡县| 盖州市| 肃宁县| 芮城县| 诸城市| 沙坪坝区| 基隆市| 巩义市| 广宗县| 额敏县|