Vulnerability Scan

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Vulnerability Scan - Presentation Transcript

    1. I-DigitalTEK Agile Development IT Solutions for Growing Business Threats and Vulnerability Assesment Real time Protection I-DigitalTEK K I IdigitalTEK
    2. Brute Force Intrusion
      • Brute Force tries a large number of Possibilities
        • Amount of time to break a 128 bit is 2 ^128 -1 or ~ “Age of Universe”
        • Xieve optimization skip non-sense combination
        • Limitation over HTTP versus TCPIP
      • Dictionary tries words and derived words from a dictionary file.
        • Password recovery utilities for Access, Quicken, MS Notes, PDF, Zip
      • Password Policy
        • # Must be between 8 - 20 characters
        • # Must include at least 1 number and 1 letter
        • # Can include uppercase and lowercase letters
        • # Can contain the following characters: @ # % * ( ) + = { } / ? ~ ; : " ' , . - _ |
        • # Must be randomly generated
      • Hint: “FTP/IMAP/POP/SMTP password breaking is not vulnerable to dictionary attacks if random value.”
    3. Cross Site Scripting
      • Web Application threats where code is injected into pages.
        • HTML-JavaScript Injection
        • DOM based
        • Non-Persistent
        • Persistent
        • Identity Attack
      • Solutions
        • Escaping or Filtering
        • Eliminating Client side scripting
        • Input Validation
    4. Code Injection
      • “ Exploitation of a Software defect to process invalid data”
      • Example of Code Injection
        • SQL Injection
        • PHP Injection
        • File Injection
        • Shell Injection
        • HTML/Script Injection
        • ASP Injection
    5. Trojan Horse
      • Term is derived from the classical story of the “Trojan Horse”
        • “ A class of computer threats that appears to perform a desirable function but in fact performs undisclosed malicious functions that allow unauthorized access to the host machine.”
      • Six main types of Trojan horse payloads are:
        • Remote Access
        • Data Destruction
        • Downloader
        • Server Trojan (Proxy, FTP , IRC, Email, HTTP/HTTPS, etc.)
        • Disable security software
        • Denial-of-Service attack (DoS)
    6. Denial of Attack
      • “ DoS attack is an attempt to make a computer resource unavailable to its intended users.”
        • One common method of attack involves saturating the target machine with external communications requests so that it cannot respond properly to legitimate traffic.
        • Smurf Attack
        • Tear Drop Attack
        • Peer-to-Peer
        • Permanent DoS
      • Protocol Analysis & “Defender” Firewall filtering
      • Honey Pot and Intrusion Detection
    7. Other Typical Attacks
        • Network sniffing.
        • Cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks.
        • Cracking recording VoIP conversations.
        • Decoding scrambled passwords.
        • Recovering wireless network keys, revealing password boxes, uncovering cached passwords.
        • Analyzing routing protocols.
        • Scan encrypted protocols such as SSH-1 and HTTPS.
        • HTTP Manipulation and Fuzzers.
    8. Web Scan Check List
      • Version Check
        • Vulnerable Web Servers
        • Vulnerable Web Server Technologies – such as “PHP 4.3.0 file disclosure and possible code execution.
      • CGI Tester
        • Checks for Web Servers Problems – Determines if dangerous HTTP methods are enabled on the web server (e.g. PUT, TRACE, DELETE)
        • Verify Web Server Technologies
      • Parameter Manipulation
        • Cross-Site Scripting (XSS) – over 40 different XSS variations are tested. - SQL Injection
        • Code Execution - Directory Traversal - File Inclusion - Script Source Code Disclosure
        • CRLF Injection - Cross Frame Scripting (XFS) - PHP Code Injection - XPath Injection
        • Full Path Disclosure - LDAP Injection - Cookie Manipulation
        • Arbitrary File creation - Arbitrary File deletion - Email Injection
        • File Tampering - URL redirection - Remote XSL inclusion
    9. Web Scan Check List
      • MultiRequest Parameter Manipulation
        • Blind SQL/XPath Injection
      • File Checks
        • Checks for Backup Files or Directories - Looks for common files (such as logs, application traces, CVS web repositories) - Cross Site Scripting in URI - Checks for Script Errors
      • Directory Checks
        • Looks for Common Files (such as logs, traces, CVS)
        • Discover Sensitive Files/Directories - Discovers Directories with Weak Permissions
        • Cross Site Scripting in Path and PHPSESSID Session Fixation. - Web Applications
        • HTTP Verb Tampering  
      • Text Search
        • Directory Listings - Source Code Disclosure - Check for Common Files
        • Check for Email Addresses - Microsoft Office Possible Sensitive Information
        • Local Path Disclosure - Error Messages
        • Trojan shell scripts (such as popular PHP shell scripts like r57shell, c99shell etc)
      • Weak Passwords
        • Weak HTTP Passwords
    10. Web Scan Check List
      • GHDB Google Hacking Database
        • Over 1200 GHDB Search Entries in the Database
      • Port Scanner and Network Alerts
        • Port scans the web server and obtains a list of open ports with banners
        • Performs complex network level vulnerability checks on open ports such as:
          • DNS Server vulnerabilities (Open zone transfer, Open recursion, cache poisoning)
          • FTP server checks (list of writable FTP directories, weak FTP passwords, anonymous access allowed)
          • Security and configuration checks for badly configured proxy servers
          • Checks for weak SNMP community strings and weak SSL cyphers
    11. Reference Material
      • I-DigitalTek - Contact US
      • Wikipedia
      • Google Hack Database

    + IDIGITALTEKIDIGITALTEK, 9 months ago

    custom

    729 views, 0 favs, 1 embeds more stats

    Website security audit

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 729
      • 725 on SlideShare
      • 4 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 0
    Most viewed embeds
    • 4 views on http://studio.i-digitaltek.net

    more

    All embeds
    • 4 views on http://studio.i-digitaltek.net

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories