Prev | Current Page 117 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"

engine.com/search?p=">
http://goodsite.com/cuteKittens.jpg
This link will appear as http://goodsite.com/cuteKittens.jpg. However, when the
victim clicks this link, it will send him or her to the HTML injection.
URL shortening web applications such as TinyURL, YATUC, ipulink.com, get-shorty.
com (and all sites implementing get-shorty), and so on, turn long URLs into very short
URLs. They do so by mapping any URL to a short URL that redirects to the long URL.
48 Hacking Exposed Web 2.0
The short URL hides the long URL, making it easier to convince even computer-savvy
people to click the link. For example, you can map an obvious HTML injection like this
http://search.engine.com/search?p=
to a discrete URL, like this
http://tinyurl.com/2optv9
Very computer-savvy users now worry about URL shortening sites like TinyURL. So
you can convince the more computer savvy users to click using other, less-popular URL
shortening web applications, or you can create your own web page with the following
code:

Note that the tag in the document.


Pages:
105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129
Szkoły policealne fryzjer w warszawie tanie pensjonaty nad morzem imprezy firmowe Konwertery Prince lion cena