Web Application Security
java app question Apr 23 2010 03:56AM
learn lids (learnlids yahoo com) (4 replies)
Re: java app question Apr 27 2010 06:56PM
Jonathan Cran (jcran 0x0e org)
> i am looking to pen test an app which is not a webapp :) . on browsing to the url it launches a java application using jnlp.

you'll probably want to take a look at the rash of java vulnerabilties
that were released recently (see: full-disclosure). one that may be of
particular use to you is the argument injection vulnerability that was
included in metasploit:
http://blog.metasploit.com/2010/04/java-web-start-argument-injection.

Make sure this type (client-side) of attack is included in your threat
model for the application, even if it isn't in-scope for the
assessment.

jcran

--
Jonathan Cran
jcran (at) 0x0e (dot) org [email concealed]
515.890.0070

This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------

[ reply ]
RE: java app question Apr 26 2010 07:22PM
Paul Melson (pmelson gmail com)
Re: java app question Apr 24 2010 10:03AM
Luca Carettoni (luca carettoni ikkisoft com)
Re: java app question Apr 23 2010 04:15PM
Rogan Dawes (lists dawes za net) (1 replies)
Re: java app question Apr 27 2010 02:52PM
¨??°º?C0D3w@lk3r?º°??¨ (c0d3walk3r gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus