01.07.2015 Views

OWASP测试指南

OWASP测试指南

OWASP测试指南

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.4.5 认 证 模 式 绕 过 测 试 (OWASP-AT-005)........................................................................................................................ 133<br />

4.4.6 记 住 密 码 和 密 码 重 置 弱 点 测 试 (OWASP-AT-006)..................................................................................................... 137<br />

4.4.7 注 销 和 浏 览 器 缓 存 管 理 测 试 (OWASP-AT-007)........................................................................................................ 140<br />

4.4.8 CAPTCHA 测 试 (OWASP-AT-008)................................................................................................................................ 144<br />

4.4.9 多 因 素 认 证 测 试 (OWASP-AT-009)............................................................................................................................ 146<br />

4.4.10 竞 争 条 件 测 试 (OWASP-AT-010).............................................................................................................................. 151<br />

4.5 会 话 管 理 测 试 ................................................................................................................................................................ 153<br />

4.5.1 会 话 管 理 模 式 测 试 (OWASP-SM-001)....................................................................................................................... 154<br />

4.5.2 COOKIES 属 性 测 试 (OWASP-SM-002)......................................................................................................................... 163<br />

4.5.3 会 话 固 定 测 试 (OWASP-SM_003)...............................................................................................................................166<br />

4.5.4 会 话 变 量 泄 漏 测 试 (OWASP-SM-004)....................................................................................................................... 169<br />

4.5.5 CSRF 测 试 (OWASP-SM-005).......................................................................................................................................172<br />

4.6 授 权 测 试 ........................................................................................................................................................................ 178<br />

4.6.1 路 径 遍 历 测 试 (OWASP-AZ-001).................................................................................................................................178<br />

4.6.2 绕 过 授 权 模 式 测 试 (OWASP-AZ-002)........................................................................................................................ 183<br />

4.6.3 提 权 测 试 (OWASP-AZ-003).........................................................................................................................................184<br />

4.7 业 务 逻 辑 测 试 (OWASP-BL-001)....................................................................................................................................186<br />

4.8 数 据 验 证 测 试 ................................................................................................................................................................192<br />

4.8.1 反 射 式 跨 站 脚 本 测 试 (OWASP-DV-001)....................................................................................................................195<br />

4.8.2 存 储 式 跨 站 脚 本 测 试 (OWASP-DV-002)....................................................................................................................200<br />

4.8.3 基 于 DOM 的 跨 站 脚 本 检 测 (OWASP-DV-003)......................................................................................................... 206<br />

4.8.4FLASH 跨 站 脚 本 测 试 (OWASP-DV-004)......................................................................................................................209<br />

4.8.5 SQL 注 入 (OWASP-DV-005)..........................................................................................................................................214<br />

4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!