12.07.2015 Views

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Application Penetration Test for Super Veda- Sample Report -Script Injection using the Comment PageAnother page where an attacker can know that any visiting innocent userwill surely view is the comments page. Injecting a script into that page,again, would result in attacking any visiting client, since the commentscode is saved on the server-side, and sent to a visiting user.The attacker can add comment that include a malicious code to any of theproducts in the site.A visiting user choosing to view the product’s comment would be receivingthis script code, and run it on his machine, enabling the attacker to havefiles sent to the 'attacker’s machine, install Trojans on the clients, and othermalicious attacks.ImpervaPage71 of73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!