E-Banking Web Security

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

2 comments

Comments 1 - 2 of 2 previous next Post a comment

Post a comment
Embed Video
Edit your comment Cancel

8 Favorites & 1 Group

E-Banking Web Security - Presentation Transcript

  1. E-Banking Web Application Security That's Where the Money Is
  2. Corporate Security Management How much can port 80 / 443 affect
  3. OWASP top 10 – NEW ! 19 May 2007
    • Cross Site Scripting (XSS)‏
    • Injection Flaws
    • Malicious File Execution
    • Insecure Direct Object Reference
    • Cross Site Request Forgery (CSRF)‏
    • Information Leakage and Improper Error Handling
  4. OWASP top 10 – NEW ! 19 May 2007
    • Broken Authentication and Session Management
    • Insecure Cryptographic Storage
    • Insecure Communications
    • Failure to Restrict URL Access
  5. PCI DSS 1.1
    • 6.6 Ensure that all web-facing applications are protected against known attacks by applying either of the following methods:
    • Having all custom application code reviewed for common vulnerabilities by an organization that specializes in application security
    • Installing an application layer firewall in front of web-facing applications.
    • Note: This method is considered a best practice until June 30, 2008, after which it becomes a requirement.
  6. Web Application Firewalls
    • Easy Deployment
    • HTTP/S Support
    • Detection Techniques
    • ProtectionTechniques
    • Virtual Patching
    • No Fixing
    • Still Vulnerable
    www.webappsec.org
    • Zero false positives
    • You are in control – Ethical Hacking
    • Push beyond low hanging fruits
    • It takes one to know one
    Layer 8 Analysis – It’s Human
    • But you don’t do the assessment
    • You see the report !
    It is a pain !
    • Certification
    • Experience
    Go For Quality Dragos Lungu [email_address] Images from www.flickr.com
    • Methodology
    • References

+ dragoslungudragoslungu, 3 years ago

custom

3111 views, 8 favs, 2 embeds more stats

More info about this document

CC Attribution-NonCommercial LicenseCC Attribution-NonCommercial License

Go to text version

  • Total Views 3111
    • 2937 on SlideShare
    • 174 from embeds
  • Comments 2
  • Favorites 8
  • Downloads 0
Most viewed embeds
  • 173 views on http://www.dragoslungu.com
  • 1 views on http://66.102.9.104

more

All embeds
  • 173 views on http://www.dragoslungu.com
  • 1 views on http://66.102.9.104

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories

Groups / Events