19.09.2017 Views

the-web-application-hackers-handbook

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 5 n Bypassing Client-Side Controls 151<br />

Attaching a Debugger<br />

Decompilation is <strong>the</strong> most complete method of understanding and compromising<br />

a browser extension. However, in large and complex components containing<br />

tens of thousands of lines of code, it is nearly always much quicker to observe <strong>the</strong><br />

component during execution, correlating methods and classes with key actions<br />

within <strong>the</strong> interface. This approach also avoids difficulties that may arise with<br />

interpreting and recompiling obfuscated bytecode. Often, achieving a specific<br />

objective is as simple as executing a key function and altering its behavior to<br />

circumvent <strong>the</strong> controls implemented within <strong>the</strong> component.<br />

Because <strong>the</strong> debugger is working at <strong>the</strong> bytecode level, it can be easily used<br />

to control and understand <strong>the</strong> flow of execution. In particular, if source code<br />

can be obtained through decompilation, breakpoints can be set on specific<br />

lines of code, allowing <strong>the</strong> understanding gained through decompilation to be<br />

supported by practical observation of <strong>the</strong> code path taken during execution.<br />

Although efficient debuggers are not fully matured for all <strong>the</strong> browser extension<br />

technologies, debugging is well supported for Java applets. By far <strong>the</strong> best<br />

resource for this is JavaSnoop, a Java debugger that can integrate Jad to decompile<br />

source code, trace variables through an <strong>application</strong>, and set breakpoints on<br />

methods to view and modify parameters. Figure 5-6 shows JavaSnoop being<br />

used to hook directly into a Java applet running in <strong>the</strong> browser. Figure 5-7<br />

shows JavaSnoop being used to tamper with <strong>the</strong> return value from a method.<br />

Figure 5-6: JavaSnoop can hook directly into an<br />

applet running in <strong>the</strong> browser<br />

NOTE It’s best to run JavaSnoop before <strong>the</strong> target applet is loaded.<br />

JavaSnoop turns off <strong>the</strong> restrictions set by your Java security policy so that it<br />

can operate on <strong>the</strong> target. In Windows, it does this by granting all permissions<br />

to all Java programs on your system, so ensure that JavaSnoop shuts down<br />

cleanly and that permissions are restored when you are finished working.<br />

An alternative tool for debugging Java is JSwat, which is highly configurable.<br />

In large projects containing many class files, it is sometimes preferable

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!