Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Javascript and actionscript Tutorial recommendations
EH-Net
May 23, 2013, 08:32:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Javascript and actionscript Tutorial recommendations  (Read 4906 times)
0 Members and 1 Guest are viewing this topic.
T_Bone
Full Member
***
Offline Offline

Posts: 199


View Profile
« on: July 20, 2010, 11:32:03 AM »

Ok, so some of you guys will probably have seen some of my posts... basically I am a newbie Pen Tester and have predominantly starting performing web app assessments.

Unfortunately I don’t have a development background, mainly sys admin and therefore am not up to speed with scripting languages.  Now I have decided to learn perl eventually but need a quick understanding of javascript and actionscript as I am not entirely sure what to look for when looking for XSS when the standard alert functions do not work.   Don’t get me wrong I have noticed that the standard <script>alert(“xss”)</script> does still get executed a lot on sites but need to get a better understanding  of Javascript and how to look for the more discreet vulnerabilities?

When decompiling flash files I generally look for Look for encryption algorithms and salts, directories you can access and enumerate, crossdomain.xml file for * as the domains it can use any more?
Any help would be appreciated?

Cheers
Logged
Equix3n-
Sr. Member
****
Online Online

Posts: 386



View Profile
« Reply #1 on: July 20, 2010, 01:09:32 PM »

Check out w3schools.com

Some websites employ filters in which case the standard alert dialog will not work. You will then have to try various evasion techniques.
eg.<script><script>alert('xss')</script></script> So if one <script></script> gets blocked the other passes through.

Cheat sheets:http://ha.ckers.org/xss.html

Logged
secureseven
Jr. Member
**
Offline Offline

Posts: 79



View Profile
« Reply #2 on: July 20, 2010, 02:36:02 PM »

This does not have much to do with learning javascript or actionscript (but the aforementioned site:w3schools is very good) but have you read The Web Application Hacker's Handbook? It's really good and in depth, and you said that you are starting new with webapp testing. Very robust and if you read a chapter at a time and apply what you learned on a vuln site, it really sticks in your head. In your case, maybe you can make mock-up web apps using javascript/actionscript and try and apply what you learned from that chapter in the book. 2 birds, 1 stone lol.
Logged

http://twitter.com/mikesantillana
eLearnSecurity Team Member.
T_Bone
Full Member
***
Offline Offline

Posts: 199


View Profile
« Reply #3 on: July 21, 2010, 02:05:33 AM »

@ secureseven

Actually I am in the process of reading through the Web Application Hackers Handbook at present.  I have been performing tasks on a list of vulnerable sites but havent yet got to the "Attacking Other users" chapter which deals with xss... ok ill be patient and will be sure to check out w3schools.
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #4 on: July 21, 2010, 10:41:43 AM »

Have you looked at the WebGoat Project?
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #5 on: July 21, 2010, 08:34:12 PM »

While this isn't a tutorial, you might have some fun working through the exercises here: http://www.hackthissite.org/
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
secureseven
Jr. Member
**
Offline Offline

Posts: 79



View Profile
« Reply #6 on: July 22, 2010, 09:25:32 AM »

Another one is : http://google-gruyere.appspot.com/#0__jarlsberg
they renamed jarlsberg to gruyere though, but same thing, just with revisements.
Logged

http://twitter.com/mikesantillana
eLearnSecurity Team Member.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.