Forums.Sureshkumar.net : A Perfect Place to Share Knowledge         Blogs     Games    Magazines    

"Sharing knowledge does not lessen your store, often it gets you more. Sharing plays a key role in relationships and bonding, happens in small steps and is assisted through community membership."

Go Back   SURESHKUMAR.NET FORUMS > TECHNICAL DISCUSSIONS > Latest Tech News & Innovations
Register FAQ Members List Calendar Games Blogs Search Today's Posts Mark Forums Read

   

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old 07-07-06, 04:21 PM   #1 (permalink)
Moderator
 
wizkid's Avatar
 
Join Date: Jun 2006
Location: India
Posts: 960
Thanks: 0
Thanked 21 Times in 20 Posts
Thanks: 0
Thanked 21 Times in 20 Posts
Rep Power: 14 wizkid has a spectacular aura about wizkid has a spectacular aura about wizkid has a spectacular aura about
Hi All,



Google Suggest and Google Maps [ref 1] are some of the notable early adopters of Ajax. Companies are now thinking of how they too can leverage it, web developers are trying to learn it, security professionals are thinking of how to secure it, and penetration testers are thinking of how to hack it







reg



wizkid
__________________
\"WHEN GOING GETS TOUGH, ONLY THE TOUGH GETS GOING\"
wizkid is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-06, 04:29 PM   #2 (permalink)
Moderator
 
Join Date: Apr 2006
Location: India
Posts: 1,733
Thanks: 2
Thanked 145 Times in 134 Posts
Thanks: 2
Thanked 145 Times in 134 Posts
Rep Power: 31 vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold vjsreevs is a splendid one to behold
While testing a regular web application, a penetration tester starts by footprinting the application. The intent of the footprint phase is to capture the requests and responses so that the tester understands how the application communicates with the server and the responses it receives.
The information is logged through local proxies such as Burp
It is important to be as complete as possible during the footprint phase so that the tester logs requests to all pages used by the application.

After that step, the tester will start the process of methodical fault injection, either manually or using automated tools, to test parameters that are passed to and from the web server.

Ajax complicates this methodology because of its asynchronous nature.
Ajax applications are typically noisier when compared to regular web applications.

An application may make multiple requests in the background even when it appears to be static to a user.

A tester has to be aware of several situations which might cause difficulties with the application testing process.

The issue of "state"
Requests initiated through timer events
Dynamic DOM updates
XML Fuzzing

The tester has to ensure that developers have not deviated from a secure architecture.
vjsreevs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to vjsreevs For This Useful Post:
AjayKumar.Kataram (25-10-08)
Old 25-10-08, 01:40 AM   #3 (permalink)
Moderator
 
Join Date: Aug 2006
Location: Hyderabad,India
Age: 29
Posts: 5,533
Thanks: 1048
Thanked 291 Times in 225 Posts
Thanks: 1,048
Thanked 291 Times in 225 Posts
Rep Power: 85 AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future AjayKumar.Kataram has a brilliant future
Re: AJAX SECURITY

nice info...
__________________
Bow to Shri Sai-Peace be to all

Ajay Kataram

visit my blog:

http://wwwajaykataram.blogspot.com/
AjayKumar.Kataram is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +6.5. The time now is 07:12 AM.





Search Engine Optimization by vBSEO 3.1.0