官术网_书友最值得收藏!

Writing the proof of concept of a report

Without the proof of concept replication steps, there is no way that the team can recreate the scenario that you just created, so it is important that you list down the steps exactly as you replicated the vulnerability. You should always treat the program owner as a newbie when explaining the proof of concept to them. This way, you can list down all of the steps in a hierarchical manner. Having simple, easy-to-follow, step-by-step instructions will help those triaging your issue to confirm its validity at the earliest opportunity. For instance, if I identified an XSS vulnerability, here is what the replication steps would look like:

  1. Go to the following [URL].
  2. Log in using your username and password (you need an account to do this).
  3. On the search box at the top-right, insert the following information:
<script>alert(document.domain);</script> 
  1. Click the Lookup button.
  2. You'll see a JavaScript popup box showing your domain.

The addition of screenshots as well as videos can greatly help the program owners to understand the vulnerability. Visual aids are always appreciated by the team. If the team is busy reviewing hundreds of reports in a day, it is possible that they may not even go through your report.

To give the program owner an idea about the severity of the flaw you found, you can show them how a malicious attacker could exploit the vulnerability you identified. You can describe a possible scenario and how and what the organization (and its clients) could lose by exploiting this flaw.

主站蜘蛛池模板: 察雅县| 温宿县| 旅游| 淳化县| 云霄县| 右玉县| 东光县| 荆州市| 肥乡县| 永安市| 新闻| 封丘县| 西吉县| 林西县| 博爱县| 马尔康县| 达尔| 泸州市| 丹巴县| 江川县| 黄陵县| 灵武市| 江达县| 确山县| 越西县| 望城县| 盘山县| 基隆市| 广饶县| 霞浦县| 绍兴市| 和平区| 开平市| 茌平县| 图木舒克市| 兰西县| 汉阴县| 天台县| 锡林浩特市| 九江市| 泾川县|