November 2017
Intermediate to advanced
452 pages
11h 46m
English
|
Threat description |
Attacker could execute operating system commands via command injection vulnerabilities |
|
Threat target |
Embedded and vendor web app. |
|
Attack techniques |
Attacker discovers flaws in DVR and vendor API communications due to weak input validation. Attacker creates code that runs within the context of the application. Attacker gains access to backend systems with custom code injected into the application. |
|
Countermeasures |
Applications perform input validation and contextual output encoding. |
Read now
Unlock full access