• Attack target: all of the above
•
•Based on
infrastructure – not the application
•Targets demo
scripts/applications and known vulnerabilities
•
• Log manifestation:
•Requests for
non-application-specific scripts/paths
•Involves path tricks or
HTTP header manipulation