Prezentarea "Securitatea Aplicatiilor Online" de la ODO

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Prezentarea "Securitatea Aplicatiilor Online" de la ODO - Presentation Transcript

    1. Securitatea aplicatiilor online
    2. Vulnerabilitati
    3. Solutii folosite
      • Servere WEB (IIS, Apache)
      • Database (MySql,Oracle, MSSQL)
      • Interpretoare (Php, PERL, ASP)
    4. Codul scris
      • SQL injection
      • XSS
      • CSRF/XSRF
      • Email Injection
      • Directory traversal
    5. Network
        • MITM attack
    6. SQL Injection
      • Atac asupra bazei de date
      http://www.example.com/view.php?id_cat=4 "SELECT * FROM data WHERE id_category = " + $_GET[‘id’] + ";" http://www.example.com/view.php?id_cat=4 OR 1=1 "SELECT * FROM data WHERE id = 1 OR 1=1;" OR 1=1
    7. why ?
      • Furtul de informatii
      • Alterarea datelor
      • Just for the fun of it
      • Se intampla si la case mai mari
        • 2007 Microsoft UK
        • 2007 UN web site
        • 2008 Kaspersky website
    8. Protectie
      • Tot input-ul trebuie verificat
      • Criptarea datelor importante
      • Backup zilnic
      • Update la database server
    9. Demonstratie
    10. XSS
      • Input-ul nu este verificat
      • Este acceptat input-ul de HTML
      • Tipuri :
        • Non-persistent
        • Persistent
    11. Non-persistent http://www.example.com?search.php?s= <script>alert(document.cookie)</script>
    12. Rezultatul :
    13. persistent
    14. CSRF/XSRF
      • Impotriva site-urilor care folosesc autentificarile din coockie/session
      • “ Hacker-ul” – are informatii despre site-ul pe care victima are access
      <img src=“http://www.other-example.com?deleteuser.php?u=vasile” />
    15. Email injection
    16. Codul din spate Nu verificam input-ul String-ul trimis la serverul de mail :
    17. Directory traversal HTTP requests
    18.  
    19. MITM attack
      • Transferul datelor
    20. Demonstratie
    21. Concluzii
      • Verifica tot input-ul
      • Informatii criptate
      • Back-up
      • Users can’t be trusted
      • Fii paranoic

    + Gabriel CurcudelGabriel Curcudel, 2 years ago

    custom

    872 views, 0 favs, 5 embeds more stats

    Prezentarea "Securitatea Aplicatiilor Online" de la more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 872
      • 791 on SlideShare
      • 81 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 5
    Most viewed embeds
    • 47 views on http://www.oamenidinonline.com
    • 16 views on http://krumel.seo-point.com
    • 13 views on http://www.krumel.ro
    • 4 views on http://www.bionyk.com
    • 1 views on http://209.85.135.104

    more

    All embeds
    • 47 views on http://www.oamenidinonline.com
    • 16 views on http://krumel.seo-point.com
    • 13 views on http://www.krumel.ro
    • 4 views on http://www.bionyk.com
    • 1 views on http://209.85.135.104

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories