Bu blogdaki popüler yayınlar
XML External Entity (XXE) Injection
In this section, we’ll explain what XML external entity injection is, describe some common examples, explain how to find and exploit various kinds of XXE injection, and summarize how to prevent XXE injection attacks. What is XML external entity injection? XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application’s processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any backend or external systems that the application itself can access. In some situations, an attacker can escalate an XXE attack to compromise the underlying server or other backend infrastructure, by leveraging the XXE vulnerability to perform server-side request forgery (SSRF) attacks. There are various types of XXE attacks: XXE Attack TypeDescriptionExploiting XXE to Retrieve FilesWhere an external entity is defined containing the contents of a file,...
Wireshark Cheat Sheet
Wireshark, whose old name is Ethereal; It is a program that can run in many operating systems such as Windows, Linux, MacOS or Solaris and can analyze all the traffic going to network cards connected to computer. Analyze over 750 protocols Can capture packets and save them to a file. Logical operators are available for all filtering. Example: http & ip.src == 192.168.0.1 Management Frame: The frame for the connection between the network device and the client. Control Frame: Controls the integrity of data traffic between the network device and the client. Data Frame: The frame on which the original data is transferred. Only to show the outgoing packets from the management frame. wlan.fc.type==0 To show incoming, outgoing packets through control frame. wlan.fc.type==1 To show packets transferred over the data frame. wlan.fc.type==2 Association lists the requests. wlan.fc.type_subtype==0 Association lists the answers. wlan.fc.type_subtype==...