10.07.2015 Views

ASP Security by Soroush Dalili - Intelligent Exploit

ASP Security by Soroush Dalili - Intelligent Exploit

ASP Security by Soroush Dalili - Intelligent Exploit

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

برنامهدر برنامه مي گرديم.‏ مي خواهيم ببينيم جايي هست كه بتوانيم درخواست SQLرا به دلخواهخود تغيير دهيم يا نه.‏ براي اين كار به دنبال پارامتر تغيير پذير در رشته SQL مي گرديم:‏7-3 شكلتصوير برنامهDreamweaver:default_content.asp -اين فايل قبلا به عنوان فايل آسيب پذير مشخص شده است.‏:default_menu_functions.asp -خطmyCatID = "SELECT * FROM ac_item WHERE Category_ID = " & catID & " ORDERBY VerticalPosition DESC, Title DESC":3686

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!