The web application hacker's handbook

finding and exploiting security flaws

2nd ed.
  • 4.7 (3 ratings)
  • 185 Want to read
  • 19 Currently reading
  • 2 Have read
Preview

Only a preview is available.

My Reading Lists:

Create a new list

  • 185 Want to read
  • 19 Currently reading
  • 2 Have read

Buy this book

Last edited by Drini
June 1, 2026 | History

The web application hacker's handbook

finding and exploiting security flaws

2nd ed.
  • 4.7 (3 ratings)
  • 185 Want to read
  • 19 Currently reading
  • 2 Have read

This book is a practical guide to discovering and exploiting security flaws in web applications. The authors explain each category of vulnerability using real-world examples, screen shots and code extracts. The book is extremely practical in focus, and describes in detail the steps involved in detecting and exploiting each kind of security weakness found within a variety of applications such as online banking, e-commerce and other web applications. The topics covered include bypassing login mechanisms, injecting code, exploiting logic flaws and compromising other users. Because every web application is different, attacking them entails bringing to bear various general principles, techniques and experience in an imaginative way. The most successful hackers go beyond this, and find ways to automate their bespoke attacks. This handbook describes a proven methodology that combines the virtues of human intelligence and computerized brute force, often with devastating results. The authors are professional penetration testers who have been involved in web application security for nearly a decade. They have presented training courses at the Black Hat security conferences throughout the world. Under the alias "PortSwigger", Dafydd developed the popular Burp Suite of web application hack tools.

Publish Date
Publisher
Wiley
Language
English
Pages
912

Buy this book

Previews available in: English

Edition Availability
Cover of: The web application hacker's handbook
The web application hacker's handbook: finding and exploiting security flaws
2011, Wiley
electronic resource : in English - 2nd ed.
Cover of: The web application hacker's handbook

Add another edition?

Book Details


First Sentence

"This book is a practical guide to discovering and exploiting security flaws in web applications."

Table of Contents

Introduction
Page xxiii
Chapter 1. Web Application (In)security
Page 1
The Evolution of Web Applications
Page 2
Common Web Application Functions
Page 4
Benefits of Web Applications
Page 5
Web Application Security
Page 6
"This Site Is Secure"
Page 7
The Core Security Problem: Users Can Submit Arbitrary Input
Page 9
Key Problem Factors
Page 10
The New Security Perimeter
Page 12
The Future of Web Application Security
Page 14
Summary
Page 15
Chapter 2. Core Defense Mechanisms
Page 17
Handling User Access
Page 18
Authentication
Page 18
Session Management
Page 19
Access Control
Page 20
Handling User Input
Page 21
Varieties of Input
Page 21
Approaches to Input Handling
Page 23
Boundary Validation
Page 25
Multistep Validation and Canonicalization
Page 28
Handling Attackers
Page 30
Handling Errors
Page 30
Maintaining Audit Logs
Page 31
Alerting Administrators
Page 33
Reacting to Attacks
Page 34
Managing the Application
Page 35
Summary
Page 36
Questions
Page 36
Chapter 3. Web Application Technologies
Page 39
The HTTP Protocol
Page 39
HTTP Requests
Page 40
HTTP Responses
Page 41
HTTP Methods
Page 42
URLs
Page 44
REST
Page 44
HTTP Headers
Page 45
Cookies
Page 47
Status Codes
Page 48
HTTPS
Page 49
HTTP Proxies
Page 49
HTTP Authentication
Page 50
Web Functionality
Page 51
Server-Side Functionality
Page 51
Client-Side Functionality
Page 57
State and Sessions
Page 66
Encoding Schemes
Page 66
URL Encoding
Page 67
Unicode Encoding
Page 67
HTML Encoding
Page 68
Base64 Encoding
Page 69
Hex Encoding
Page 69
Remoting and Serialization Frameworks
Page 70
Next Steps
Page 70
Questions
Page 71
Chapter 4. Mapping the Application
Page 73
Enumerating Content and Functionality
Page 74
Web Spidering
Page 74
User-Directed Spidering
Page 77
Discovering Hidden Content
Page 80
Application Pages Versus Functional Paths
Page 93
Discovering Hidden Parameters
Page 96
Analyzing the Application
Page 97
Identifying Entry Points for User Input
Page 98
Identifying Server-Side Technologies
Page 101
Identifying Server-Side Functionality
Page 107
Mapping the Attack Surface
Page 111
Summary
Page 114
Questions
Page 114
Chapter 5. Bypassing Client-Side Controls
Page 117
Transmitting Data Via the Client
Page 118
Hidden Form Fields
Page 118
HTTP Cookies
Page 121
URL Parameters
Page 121
The Referer Header
Page 122
Opaque Data
Page 123
The ASP.NET ViewState
Page 124
Capturing User Data: HTML Forms
Page 127
Length Limits
Page 128
Script-Based Validation
Page 129
Disabled Elements
Page 131
Capturing User Data: Browser Extensions
Page 133
Common Browser Extension Technologies
Page 134
Approaches to Browser Extensions
Page 135
Intercepting Traffic from Browser Extensions
Page 135
Decompiling Browser Extensions
Page 139
Attaching a Debugger
Page 151
Native Client Components
Page 153
Handling Client-Side Data Securely
Page 154
Transmitting Data Via the Client
Page 154
Validating Client-Generated Data
Page 155
Logging and Alerting
Page 156
Summary
Page 156
Questions
Page 157
Chapter 6. Attacking Authentication
Page 159
Authentication Technologies
Page 160
Design Flaws in Authentication Mechanisms
Page 161
Bad Passwords
Page 161
Brute-Forcible Login
Page 162
Verbose Failure Messages
Page 166
Vulnerable Transmission of Credentials
Page 169
Password Change Functionality
Page 171
Forgotten Password Functionality
Page 173
"Remember Me" Functionality
Page 176
User Impersonation Functionality
Page 178
Incomplete Validation of Credentials
Page 180
Nonunique Usernames
Page 181
Predictable Usernames
Page 182
Predictable Initial Passwords
Page 183
Insecure Distribution of Credentials
Page 184
Implementation Flaws in Authentication
Page 185
Fail-Open Login Mechanisms
Page 185
Defects in Multistage Login Mechanisms
Page 186
Insecure Storage of Credentials
Page 190
Securing Authentication
Page 191
Use Strong Credentials
Page 192
Handle Credentials Secretively
Page 192
Validate Credentials Properly
Page 193
Prevent Information Leakage
Page 195
Prevent Brute-Force Attacks
Page 196
Prevent Misuse of the Password Change Function
Page 199
Prevent Misuse of the Account Recovery Function
Page 199
Log, Monitor, and Notify
Page 201
Summary
Page 201
Questions
Page 202
Chapter 7. Attacking Session Management
Page 205
The Need for State
Page 206
Alternatives to Sessions
Page 208
Weaknesses in Token Generation
Page 210
Meaningful Tokens
Page 210
Predictable Tokens
Page 213
Encrypted Tokens
Page 223
Weaknesses in Session Token Handling
Page 233
Disclosure of Tokens on the Network
Page 234
Disclosure of Tokens in Logs
Page 237
Vulnerable Mapping of Tokens to Sessions
Page 240
Vulnerable Session Termination
Page 241
Client Exposure to Token Hijacking
Page 243
Liberal Cookie Scope
Page 244
Securing Session Management
Page 248
Generate Strong Tokens
Page 248
Protect Tokens Throughout Their Life Cycle
Page 250
Log, Monitor, and Alert
Page 253
Summary
Page 254
Questions
Page 255
Chapter 8. Attacking Access Controls
Page 257
Common Vulnerabilities
Page 258
Completely Unprotected Functionality
Page 259
Identifier-Based Functions
Page 261
Multistage Functions
Page 262
Static Files
Page 263
Platform Misconfiguration
Page 264
Insecure Access Control Methods
Page 265
Attacking Access Controls
Page 266
Testing with Different User Accounts
Page 267
Testing Multistage Processes
Page 271
Testing with Limited Access
Page 273
Testing Direct Access to Methods
Page 276
Testing Controls Over Static Resources
Page 277
Testing Restrictions on HTTP Methods
Page 278
Securing Access Controls
Page 278
A Multilayered Privilege Model
Page 280
Summary
Page 284
Questions
Page 284
Chapter 9. Attacking Data Stores
Page 287
Injecting into Interpreted Contexts
Page 288
Bypassing a Login
Page 288
Injecting into SQL
Page 291
Exploiting a Basic Vulnerability
Page 292
Injecting into Different Statement Types
Page 294
Finding SQL Injection Bugs
Page 298
Fingerprinting the Database
Page 303
The UNION Operator
Page 304
Extracting Useful Data
Page 308
Extracting Data with UNION
Page 308
Bypassing Filters
Page 311
Second-Order SQL Injection
Page 313
Advanced Exploitation
Page 314
Beyond SQL Injection: Escalating the Database Attack
Page 325
Using SQL Exploitation Tools
Page 328
SQL Syntax and Error Reference
Page 332
Preventing SQL Injection
Page 338
Injecting into NoSQL
Page 342
Injecting into MongoDB
Page 343
Injecting into XPath
Page 344
Subverting Application Logic
Page 345
Informed XPath Injection
Page 346
Blind XPath Injection
Page 347
Finding XPath Injection Flaws
Page 348
Preventing XPath Injection
Page 349
Injecting into LDAP
Page 349
Exploiting LDAP Injection
Page 351
Finding LDAP Injection Flaws
Page 353
Preventing LDAP Injection
Page 354
Summary
Page 354
Questions
Page 354
Chapter 10. Attacking Back-End Components
Page 357
Injecting OS Commands
Page 358
Example 1: Injecting Via Perl
Page 358
Example 2: Injecting Via ASP
Page 360
Injecting Through Dynamic Execution
Page 362
Finding OS Command Injection Flaws
Page 363
Finding Dynamic Execution Vulnerabilities
Page 366
Preventing OS Command Injection
Page 367
Preventing Script Injection Vulnerabilities
Page 368
Manipulating File Paths
Page 368
Path Traversal Vulnerabilities
Page 368
File Inclusion Vulnerabilities
Page 381
Injecting into XML Interpreters
Page 383
Injecting XML External Entities
Page 384
Injecting into SOAP Services
Page 386
Finding and Exploiting SOAP Injection
Page 389
Preventing SOAP Injection
Page 390
Injecting into Back-end HTTP Requests
Page 390
Server-side HTTP Redirection
Page 390
HTTP Parameter Injection
Page 393
Injecting into Mail Services
Page 397
E-mail Header Manipulation
Page 398
SMTP Command Injection
Page 399
Finding SMTP Injection Flaws
Page 400
Preventing SMTP Injection
Page 402
Summary
Page 402
Questions
Page 403
Chapter 11. Attacking Application Logic
Page 405
The Nature of Logic Flaws
Page 406
Real-World Logic Flaws
Page 406
Example 1: Asking the Oracle
Page 407
Example 2: Fooling a Password Change Function
Page 409
Example 3: Proceeding to Checkout
Page 410
Example 4: Rolling Your Own Insurance
Page 412
Example 5: Breaking the Bank
Page 414
Example 6: Beating a Business Limit
Page 416
Example 7: Cheating on Bulk Discounts
Page 418
Example 8: Escaping from Escaping
Page 419
Example 9: Invalidating Input Validation
Page 420
Example 10: Abusing a Search Function
Page 422
Example 11: Snarfing Debug Messages
Page 424
Example 12: Racing Against the Login
Page 426
Avoiding Logic Flaws
Page 428
Summary
Page 429
Questions
Page 430
Chapter 12. Attacking Users: Cross-Site Scripting
Page 431
Varieties of XSS
Page 433
Reflected XSS Vulnerabilities
Page 434
Stored XSS Vulnerabilities
Page 438
DOM-Based XSS Vulnerabilities
Page 440
XSS Attacks in Action
Page 442
Real-World XSS Attacks
Page 442
Payloads for XSS Attacks
Page 443
Delivery Mechanisms for XSS Attacks
Page 447
Finding and Exploiting XSS Vulnerabilities
Page 451
Finding and Exploiting Reflected XSS Vulnerabilities
Page 452
Finding and Exploiting Stored XSS Vulnerabilities
Page 481
Finding and Exploiting DOM-Based XSS Vulnerabilities
Page 487
Preventing XSS Attacks
Page 492
Preventing Reflected and Stored XSS
Page 492
Preventing DOM-Based XSS
Page 496
Summary
Page 498
Questions
Page 498
Chapter 13. Attacking Users: Other Techniques
Page 501
Inducing User Actions
Page 501
Request Forgery
Page 502
UI Redress
Page 511
Capturing Data Cross-Domain
Page 515
Capturing Data by Injecting HTML
Page 516
Capturing Data by Injecting CSS
Page 517
JavaScript Hijacking
Page 519
The Same-Origin Policy Revisited
Page 524
The Same-Origin Policy and Browser Extensions
Page 525
The Same-Origin Policy and HTML5
Page 528
Crossing Domains with Proxy Service Applications
Page 529
Other Client-Side Injection Attacks
Page 531
HTTP Header Injection
Page 531
Cookie Injection
Page 536
Open Redirection Vulnerabilities
Page 540
Client-Side SQL Injection
Page 547
Client-Side HTTP Parameter Pollution
Page 548
Local Privacy Attacks
Page 550
Persistent Cookies
Page 550
Cached Web Content
Page 551
Browsing History
Page 552
Autocomplete
Page 552
Flash Local Shared Objects
Page 553
Silverlight Isolated Storage
Page 553
Internet Explorer userData
Page 554
HTML5 Local Storage Mechanisms
Page 554
Preventing Local Privacy Attacks
Page 554
Attacking ActiveX Controls
Page 555
Finding ActiveX Vulnerabilities
Page 556
Preventing ActiveX Vulnerabilities
Page 558
Attacking the Browser
Page 559
Logging Keystrokes
Page 560
Stealing Browser History and Search Queries
Page 560
Enumerating Currently Used Applications
Page 560
Port Scanning
Page 561
Attacking Other Network Hosts
Page 561
Exploiting Non-HTTP Services
Page 562
Exploiting Browser Bugs
Page 563
DNS Rebinding
Page 563
Browser Exploitation Frameworks
Page 564
Man-in-the-Middle Attacks
Page 566
Summary
Page 568
Questions
Page 568
Chapter 14. Automating Customized Attacks
Page 571
Uses for Customized Automation
Page 572
Enumerating Valid Identifiers
Page 573
The Basic Approach
Page 574
Detecting Hits
Page 574
Scripting the Attack
Page 576
JAttack
Page 577
Harvesting Useful Data
Page 583
Fuzzing for Common Vulnerabilities
Page 586
Putting It All Together: Burp Intruder
Page 590
Barriers to Automation
Page 602
Session-Handling Mechanisms
Page 602
CAPTCHA Controls
Page 610
Summary
Page 613
Questions
Page 613
Chapter 15. Exploiting Information Disclosure
Page 615
Exploiting Error Messages
Page 615
Script Error Messages
Page 616
Stack Traces
Page 617
Informative Debug Messages
Page 618
Server and Database Messages
Page 619
Using Public Information
Page 623
Engineering Informative Error Messages
Page 624
Gathering Published Information
Page 625
Using Inference
Page 626
Preventing Information Leakage
Page 627
Use Generic Error Messages
Page 628
Protect Sensitive Information
Page 628
Minimize Client-Side Information Leakage
Page 629
Summary
Page 629
Questions
Page 630
Chapter 16. Attacking Native Compiled Applications
Page 633
Buffer Overflow Vulnerabilities
Page 634
Stack Overflows
Page 634
Heap Overflows
Page 635
"Off-by-One" Vulnerabilities
Page 636
Detecting Buffer Overflow Vulnerabilities
Page 639
Integer Vulnerabilities
Page 640
Integer Overflows
Page 640
Signedness Errors
Page 641
Detecting Integer Vulnerabilities
Page 642
Format String Vulnerabilities
Page 643
Detecting Format String Vulnerabilities
Page 644
Summary
Page 645
Questions
Page 645
Chapter 17. Attacking Application Architecture
Page 647
Tiered Architectures
Page 647
Attacking Tiered Architectures
Page 648
Securing Tiered Architectures
Page 654
Shared Hosting and Application Service Providers
Page 656
Virtual Hosting
Page 657
Shared Application Services
Page 657
Attacking Shared Environments
Page 658
Securing Shared Environments
Page 665
Summary
Page 667
Questions
Page 667
Chapter 18. Attacking the Application Server
Page 669
Vulnerable Server Configuration
Page 670
Default Credentials
Page 670
Default Content
Page 671
Directory Listings
Page 677
WebDAV Methods
Page 679
The Application Server as a Proxy
Page 682
Misconfigured Virtual Hosting
Page 683
Securing Web Server Configuration
Page 684
Vulnerable Server Software
Page 684
Application Framework Flaws
Page 685
Memory Management Vulnerabilities
Page 687
Encoding and Canonicalization
Page 689
Finding Web Server Flaws
Page 694
Securing Web Server Software
Page 695
Web Application Firewalls
Page 697
Summary
Page 699
Questions
Page 699
Chapter 19. Finding Vulnerabilities in Source Code
Page 701
Approaches to Code Review
Page 702
Black-Box Versus White-Box Testing
Page 702
Code Review Methodology
Page 703
Signatures of Common Vulnerabilities
Page 704
Cross-Site Scripting
Page 704
SQL Injection
Page 705
Path Traversal
Page 706
Arbitrary Redirection
Page 707
OS Command Injection
Page 708
Backdoor Passwords
Page 708
Native Software Bugs
Page 709
Source Code Comments
Page 710
The Java Platform
Page 711
Identifying User-Supplied Data
Page 711
Session Interaction
Page 712
Potentially Dangerous APIs
Page 713
Configuring the Java Environment
Page 716
ASP.NET
Page 718
Identifying User-Supplied Data
Page 718
Session Interaction
Page 719
Potentially Dangerous APIs
Page 720
Configuring the ASP.NET Environment
Page 723
PHP
Page 724
Identifying User-Supplied Data
Page 724
Session Interaction
Page 727
Potentially Dangerous APIs
Page 727
Configuring the PHP Environment
Page 732
Perl
Page 735
Identifying User-Supplied Data
Page 735
Session Interaction
Page 736
Potentially Dangerous APIs
Page 736
Configuring the Perl Environment
Page 739
JavaScript
Page 740
Database Code Components
Page 741
SQL Injection
Page 741
Calls to Dangerous Functions
Page 742
Tools for Code Browsing
Page 743
Summary
Page 744
Questions
Page 744
Chapter 20. A Web Application Hacker's Toolkit
Page 747
Web Browsers
Page 748
Internet Explorer
Page 748
Firefox
Page 749
Chrome
Page 750
Integrated Testing Suites
Page 751
How the Tools Work
Page 751
Testing Work Flow
Page 769
Alternatives to the Intercepting Proxy
Page 771
Standalone Vulnerability Scanners
Page 773
Vulnerabilities Detected by Scanners
Page 774
Inherent Limitations of Scanners
Page 776
Technical Challenges Faced by Scanners
Page 778
Current Products
Page 781
Using a Vulnerability Scanner
Page 783
Other Tools
Page 785
Wikto/Nikto
Page 785
Firebug
Page 785
Hydra
Page 785
Custom Scripts
Page 786
Summary
Page 789
Chapter 21. A Web Application Hacker's Methodology
Page 791
General Guidelines
Page 793
1. Map the Application's Content
Page 795
1.1. Explore Visible Content
Page 795
1.2. Consult Public Resources
Page 796
1.3. Discover Hidden Content
Page 796
1.4. Discover Default Content
Page 797
1.5. Enumerate Identifier-Specified Functions
Page 797
1.6. Test for Debug Parameters
Page 798
2. Analyze the Application
Page 798
2.1. Identify Functionality
Page 798
2.2. Identify Data Entry Points
Page 799
2.3. Identify the Technologies Used
Page 799
2.4. Map the Attack Surface
Page 800
3. Test Client-Side Controls
Page 800
3.1. Test Transmission of Data Via the Client
Page 801
3.2. Test Client-Side Controls Over User Input
Page 801
3.3. Test Browser Extension Components
Page 802
4. Test the Authentication Mechanism
Page 805
4.1. Understand the Mechanism
Page 805
4.2. Test Password Quality
Page 806
4.3. Test for Username Enumeration
Page 806
4.4. Test Resilience to Password Guessing
Page 807
4.5. Test Any Account Recovery Function
Page 807
4.6. Test Any Remember Me Function
Page 808
4.7. Test Any Impersonation Function
Page 808
4.8. Test Username Uniqueness
Page 809
4.9. Test Predictability of Autogenerated Credentials
Page 809
4.10. Check for Unsafe Transmission of Credentials
Page 810
4.11. Check for Unsafe Distribution of Credentials
Page 810
4.12. Test for Insecure Storage
Page 811
4.13. Test for Logic Flaws
Page 811
4.14. Exploit Any Vulnerabilities to Gain Unauthorized Access
Page 813
5. Test the Session Management Mechanism
Page 814
5.1. Understand the Mechanism
Page 814
5.2. Test Tokens for Meaning
Page 815
5.3. Test Tokens for Predictability
Page 816
5.4. Check for Insecure Transmission of Tokens
Page 817
5.5. Check for Disclosure of Tokens in Logs
Page 817
5.6. Check Mapping of Tokens to Sessions
Page 818
5.7. Test Session Termination
Page 818
5.8. Check for Session Fixation
Page 819
5.9. Check for CSRF
Page 820
5.10. Check Cookie Scope
Page 820
6. Test Access Controls
Page 821
6.1. Understand the Access Control Requirements
Page 821
6.2. Test with Multiple Accounts
Page 822
6.3. Test with Limited Access
Page 822
6.4. Test for Insecure Access Control Methods
Page 823
7. Test for Input-Based Vulnerabilities
Page 824
7.1. Fuzz All Request Parameters
Page 824
7.2. Test for SQL Injection
Page 827
7.3. Test for XSS and Other Response Injection
Page 829
7.4. Test for OS Command Injection
Page 832
7.5. Test for Path Traversal
Page 833
7.6. Test for Script Injection
Page 835
7.7. Test for File Inclusion
Page 835
8. Test for Function-Specific Input Vulnerabilities
Page 836
8.1. Test for SMTP Injection
Page 836
8.2. Test for Native Software Vulnerabilities
Page 837
8.3. Test for SOAP Injection
Page 839
8.4. Test for LDAP Injection
Page 839
8.5. Test for XPath Injection
Page 840
8.6. Test for Back-End Request Injection
Page 841
8.7. Test for XXE Injection
Page 841
9. Test for Logic Flaws
Page 842
9.1. Identify the Key Attack Surface
Page 842
9.2. Test Multistage Processes
Page 842
9.3. Test Handling of Incomplete Input
Page 843
9.4. Test Trust Boundaries
Page 844
9.5. Test Transaction Logic
Page 844
10. Test for Shared Hosting Vulnerabilities
Page 845
10.1. Test Segregation in Shared Infrastructures
Page 845
10.2. Test Segregation Between ASP-Hosted Applications
Page 845
11. Test for Application Server Vulnerabilities
Page 846
11.1. Test for Default Credentials
Page 846
11.2. Test for Default Content
Page 847
11.3. Test for Dangerous HTTP Methods
Page 847
11.4. Test for Proxy Functionality
Page 847
11.5. Test for Virtual Hosting Misconfiguration
Page 847
11.6. Test for Web Server Software Bugs
Page 848
11.7. Test for Web Application Firewalling
Page 848
12. Miscellaneous Checks
Page 849
12.1. Check for DOM-Based Attacks
Page 849
12.2. Check for Local Privacy Vulnerabilities
Page 850
12.3. Check for Weak SSL Ciphers
Page 851
12.4. Check Same-Origin Policy Configuration
Page 851
13. Follow Up Any Information Leakage
Page 852
Index
Page 853

Edition Notes

Electronic reproduction. Palo Alto, Calif. : ebrary, 2011. Available via World Wide Web. Access may be limited to ebrary affiliated libraries.

Published in
Indianapolis
Copyright Date
2011

Contributors

Author
Marcus Pinto

The Physical Object

Format
[electronic resource] :
Pagination
912 p.
Number of pages
912

Edition Identifiers

Open Library
OL25567215M
ISBN 10
1118026470
ISBN 13
9781118026472, 9781118175224, 978-1-118-17524-8, 978-1-118-17523-1
LCCN
2011934639
OCLC/WorldCat
759159321, 786167000

Work Identifiers

Work ID
OL13814659W

Community Reviews (3)

Difficulty 2 Intermediate 33% Advanced 33% Beginner 33% Content Warnings 1 Adult themes 100%

Lists

Download catalog record: RDF / JSON