Thứ Sáu, 30 tháng 11, 2012

SERVER-SIDE INCLUDES (SSI) INJECTION


SERVER-SIDE INCLUDES (SSI) INJECTION | Juno_okyo's Blog
It is a web attack were a remote attacker can execute commands on the server remotely, SSI Injections are used to execute some content before the web page is loaded or before the web page displayed to the user. SSI are exploited by injection mailicious codes in HTML web pages.

SSI Injection is a bit similiar to XSS attacks, we check the website, if its vulnerable or not by executing codes/commands in the search boxs, headers, cookies like we do in the case of XSS.

READ MORE »

Không có nhận xét nào:

Đăng nhận xét