CS 161: Computer Security Prof. Raluca Ada Popa

• Look for “/etc/passwd” and/or “../../” • Pros: – No problems with HTTP complexities like %-escapes – Works for encrypted HTTPS! (because it gets decrypted at endpoint host) • Issues: – Have to add code to each (possibly different) web server • And that effort only helps with detecting web server attacks ................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download