November 2017
Intermediate to advanced
452 pages
11h 46m
English
The process of finding command injectable pages within an embedded web application is rather trivial. The first places within an application we want to examine are diagnostic pages that make use of system commands, such as ping or traceroute, but also configuration setting pages for daemons, such as SMB, PPTP, or FTP. If we have acquired firmware or gained access to a target device's console, it's always best to statically analyze vulnerable scripts and functions that the device executes and validate potential findings discovered via dynamic analysis:
Read now
Unlock full access