База знаний

4.11 Клиентская часть

:::tip Формат страницы

Порядок действий описан по‑русски. В методике сохранены заголовки (частично локализованы типовые термины), таблицы, иллюстрации и блоки кода: команды и параметры на английском, без перевода синтаксиса.

:::

Порядок действий

1. Откройте соответствующий подраздел методики тестирования веб‑приложений.
2. Зафиксируйте объект, роль и предпосылки теста.
3. Пройдите сценарии по чек‑листу, сохраняя запросы, ответы и выводы.
4. Ниже — структура темы и примеры команд на английском.

Методика

4.11.1 Testing for DOM-Based Cross Site Scripting

document.URL|document.documentURI|document.URLUnencoded|document.baseURI|location.search|document.cookie|document.referrer|location.

document.write(|document.writeln(|document.domain|w.innerHTML|w.outerHTML|w.insertAdjacentHTML|w.onevent

​

4.11.2 Testing for JavaScript Execution

​

4.11.3 Testing for HTML Injection

​

4.11.4 Testing for Client-side URL Redirect

[?&](url|link|redirect|target|site|page|navigate|ref|callback|host|return|next|returnurl|redirectUrl)=

​

4.11.5 Testing for CSS Injection

​

4.11.6 Testing for Client-side Resource Manipulation

[?&](file|path|document|folder|dir|download|resource|view|load|template|img|image)=|.src=

​

4.11.7 Testing Cross Origin Resource Sharing

​

4.11.8 Testing for Cross Site Flashing

​

4.11.9 Testing for Clickjacking

<!-- clickjacking.html: -->
<html>
   <head>
     <title>Clickjack test page</title>
   </head>
   <body>
     <h1>Website is vulnerable to clickjacking attacks!</h1>
     <p>Embebed in a iframe for clickjackings attacks</p> 
     <p>Authenticated page with privilege actions</p> 
     <input type="button" value="Vulnerable" style="position:absolute;top:280;left:450;background-color:red;color:white;padding: 10px 15px;">
     <iframe src="https://example.com/" style="opacity:0.5; filter:alpha(opacity=30)" width="1500" height="1000"></iframe>
   </body>
</html>

<!-- Attacker’s top frame (pre-clickjacking.html): -->
<h1>Double Framing Attack (First Frame)</h1>
<iframe src="clickjacking.html" width="3000" height="2000"></iframe>

<iframe src="http://example.org" security="restricted"></iframe>

<iframe src="http://example.org" sandbox></iframe>

<h1>www.fictitious.site</h1>
<script>
    window.onbeforeunload = function()
    {
        return " Do you want to leave fictitious.site?";
    }
</script>
<iframe src="http://example.org">

​

4.11.10 Testing WebSockets

​

4.11.11 Testing Web Messaging

​

4.11.12 Testing Browser Storage

​

4.11.13 Testing for Cross Site Script Inclusion

​

—