Parameter name injection - Not tested by WebInspect 9.x

Danux <[email protected]> Thu, 9 Aug 2012 01:35:08 -0500
Newsgroups gmane.comp.security.websecurity,gmane.comp.security.web-applications
Message-ID <CAL7A2DxkYiaik=BYazi=L+r09-R7-ty70bo1H1bg4hXwZf+rwA@mail.gmail.com>
Old technique but still out of testers' radar. Ninety nine percent
(99%) of tools concentrate on identifying and injecting malicious code
into parameter values, also 99% of Developers concentrate on html
encoding parameter values specially to prevent client-side attacks,
but what about parameter names? is it worth to test/protect them?
Definitely it is. Highly exploitable in content management frameworks
which creates links or other DOM objects on the fly.

Surprisingly, WebInspect 9.x do not care about testing parameter
names, at least not when using its XSS-scan policy. Do you have
experience with other tools in this matter?

I prepared an example of this attack if interested:

http://danuxx.blogspot.com/2012/07/postget-parameters-name-injection.html


Enjoy it.


-- 
DanUx

_______________________________________________
The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

[email protected]
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org