19.09.2017 Views

the-web-application-hackers-handbook

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 13 n Attacking Users: O<strong>the</strong>r Techniques 553<br />

Flash Local Shared Objects<br />

The Flash browser extension implements its own local storage mechanism called<br />

Local Shared Objects (LSOs), also called Flash cookies. In contrast to most o<strong>the</strong>r<br />

mechanisms, data persisted in LSOs is shared between different browser types,<br />

provided that <strong>the</strong>y have <strong>the</strong> Flash extension installed.<br />

HACK STEPS<br />

1. Several plug-ins are available for Firefox, such as BetterPrivacy, which can<br />

be used to browse <strong>the</strong> LSO data created by individual <strong>application</strong>s.<br />

2. You can review <strong>the</strong> contents of <strong>the</strong> raw LSO data directly on disk. The<br />

location of this data depends on <strong>the</strong> browser and operating system. For<br />

example, on recent versions of Internet Explorer, <strong>the</strong> LSO data resides<br />

within <strong>the</strong> following folder structure:<br />

C:\Users\{username}\AppData\Roaming\Macromedia\Flash Player\<br />

#SharedObjects\{random}\{domain name}\{store name}\{name of<br />

SWF file}<br />

TRY IT!<br />

http://mdsec.net/auth/245/<br />

Silverlight Isolated Storage<br />

The Silverlight browser extension implements its own local storage mechanism<br />

called Silverlight Isolated Storage.<br />

HACK STEPS<br />

You can review <strong>the</strong> contents of <strong>the</strong> raw Silverlight Isolated Storage data<br />

directly on disk. For recent versions of Internet Explorer, this data resides<br />

within a series of deeply nested, randomly named folders at <strong>the</strong> following<br />

location:<br />

C:\Users\{username}\AppData\LocalLow\Microsoft\Silverlight\<br />

TRY IT!<br />

http://mdsec.net/auth/239/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!