2 weeks ago
2 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.
[caption id="attachment_808" align="aligncenter" width="650"]
Authentication bypass using cookie tampering and burp suite intruder[/caption]
The method of authentication bypass using cookie tampering I am going to discuss here is totally a case study of bug I found during pentesting of a social network based web application (website name is kept confidential) .While surfing the site and noticing the parameters going forth and back in burpsuite , a token came into my notice named authentication_token that was getting generated every time I make a login attempt and also it was getting verified on server-side
POST /edit-profile HTTP/1.1 Accept: text/html, application/xhtml+xml / Content-Type: application/x-www-form-urlencoded Accept-Encoding: gzip, deflate Cookie: authentication_token=56S-A31-5450 Content-Length:90 Connection: Keep-Alive Accept-Language: en-US id=5631
Share your views on Autauthentication bypass using cookie tampering