Testing Your Forms for Hijacking Vulnerability
By Will Bontrager2005-10-07
DISCLAIMER: Experience has taught me it is impossible to know everything in cracker minds. Common sense security precautions when programming software go a long way to reducing vulnerabilities. And I've learned to anticipate things and reduce vulnerabilities ahead of time. But I can not, and I do not claim to, know everything software crackers have tried and will try in the future.
Look at this article as a "how-to" for testing your forms for a specific vulnerability, hijacking by inserting certain information into the header of email your form processing software sends out.
These tests may not be exhaustive. Crackers have devious minds and may even now be thinking of hijacking methods I haven't considered.
This article will, however, show you how to discover currently targeted vulnerabilities your form processing software might have, vulnerabilities mentioned in the "Web Page Form Anti-Hijacking Considerations" article found at http://willmaster.com/hijack1 (demonstrates how to modify software to close the hijacking vulnerability).
Tutorial pages:
|
Copyright 2004 Bontrager Connection, LLC
|
|||||||||
You might also want to check these out:
|
Link to This Tutorial Page!

