Похожие чаты

Hi mates I have recently started to study cyber security

and as I understood that strong server side validation is tough enemy for hackers, so which tools of encoding - obfuscation do they use to break server side validation? Surprisingly Google gives little information about it

8 ответов

2 просмотра

Obfuscation is not security

Nobody will willingly give you that information

Börke(МБорке)- Автор вопроса
Sharuzzaman Ahmat Raslan
Obfuscation is not security

Correct me if I am wrong but I used to think that obfuscation (methods or tools) are used for making the validation system confused so hackers can do request/response manipulation, no?

Börke(МБорке)
Correct me if I am wrong but I used to think that ...

No. Obfuscation is a way to hide something, but it is not encryption. ROT13 is an example of obfuscation. PGP keypair is encryption

Börke(МБорке)- Автор вопроса
Sharuzzaman Ahmat Raslan
No. Obfuscation is a way to hide something, but it...

Mate, then can you explain that how do hackers deal with server side validation ?(besides social engineering)

Börke(МБорке)
Mate, then can you explain that how do hackers dea...

Look for buffer overflows, look for SQL injection sites, look for timing attacks

Börke(МБорке)- Автор вопроса
Börke(МБорке)
Ok thx for the advice. Yes these are common attack...

You can also look for what parser they use to see if you can get it to do more creative things (lookup "the treachery of files" conference and the mag "POC || GTFO")

Похожие вопросы

Обсуждают сегодня

VIP-397 BNBx Oracle implementation upgrade Summary This proposal, if approved, will upgrade the implementation of the BNBx Oracle contract on Venus from version 1 (V1) to v...
Venus Announcements
2
Всем привет! Имеется функция: function IsValidChar(ch: UTF8Char): Boolean; var i: Integer; ValidChars: AnsiString; begin ValidChars := 'abcdefghijklmnopqrstuvwxyzABCDE...
Евгений
44
Ну вот просто даже давайте вот как. Какой нибудь конкретный кейс, можете в пример привести, где бч работает и приносит прикладную пользу, а не просто что бы было? Не крипту.
Alexander Andreev
22
For all those that keep asking why no pump? why this ? and why that...? Please close ur ewt chart and open 2 others - TOTAL (total mc) and BTC.D (btc dominance). Maybe BTC a...
Inn3r_G
19
объясните пожалуйста, почему функция не работает должным образом? вроде должно брать активное окно сравнивать его размер с размером экрана, и если есть совпадение = true прове...
JF
12
"Since pnut can flip FTM easily, I'm swapping my FTM to pnut and hoping for a easy x5-x10" Perfect recipe for disaster. NFA but chances are, you'll end up as exit liquidity ...
C. A.
7
Ready for some fun AND a chance to win TKO Tokens? Join us for exciting minigames in our Telegram group! 🕒 Don’t miss out—games start on today 25 October 2024, at 8 PM! Ge...
Milkyway | Tokocrypto
255
AMD status update? No longer in the plan but something might be around the corner later on Chinese partner? No longer in the plan. This market does not seem to be the top ...
Ben
6
207$ but only received 170$. what the hell?
htt
10
да кстати заметил всюда почему то всех сюда прёт, ни в одном чате столько ботов не прёт как сюда.. Может чота надо доработать?
REDis
15
Карта сайта