際際滷

際際滷Share a Scribd company logo
Securitatea aplicatiilor online
Vulnerabilitati
Solutii folosite Servere WEB (IIS, Apache) Database (MySql,Oracle, MSSQL) Interpretoare (Php, PERL, ASP)
Codul scris SQL injection XSS CSRF/XSRF Email Injection Directory traversal
Network MITM attack
SQL Injection Atac asupra bazei de date http://www.example.com/view.php?id_cat=4 "SELECT * FROM data WHERE id_category = " +  $_GET[id]  + ";"  http://www.example.com/view.php?id_cat=4 OR 1=1 "SELECT * FROM data WHERE id = 1 OR 1=1;"  OR 1=1
why ? Furtul de informatii Alterarea datelor Just for the fun of it Se intampla si la case mai mari  2007 Microsoft UK  2007 UN web site 2008 Kaspersky website
Protectie Tot input-ul trebuie verificat Criptarea datelor importante Backup zilnic Update la database server
Demonstratie
XSS Input-ul nu este verificat Este acceptat input-ul de HTML Tipuri : Non-persistent Persistent
Non-persistent http://www.example.com?search.php?s= <script>alert(document.cookie)</script>
Rezultatul :
persistent
CSRF/XSRF Impotriva site-urilor care folosesc  autentificarile din coockie/session  Hacker-ul  are informatii despre site-ul pe care victima are access <img src=/slideshow/prezentarea-securitatea-aplicatiilor-online-de-la-odo/540898/http:/www.other-example.com?deleteuser.php?u=vasile />
Email injection
Codul din spate Nu verificam input-ul String-ul trimis la serverul de mail :
Directory traversal HTTP requests
油
MITM attack
Transferul datelor
Demonstratie
Concluzii Verifica tot input-ul Informatii criptate Back-up  Users cant be trusted Fii paranoic
Ad

Recommended

Owasp and friends
Owasp and friends
Ma転vydas Skuodas
Joomla Security
Joomla Security
Ruth Cheesley
WordPress Security - What to do, What NOT to do
WordPress Security - What to do, What NOT to do
WordPress Trivandrum
WordPress Security Best Practices
WordPress Security Best Practices
Jason Yingling
Joomla sp辿cialiste
Joomla sp辿cialiste
Romain Caisse
Prezentare Haipa despre bloguri
Prezentare Haipa despre bloguri
Gabriel Curcudel
KFP New Media & Prevention
KFP New Media & Prevention
LaDonna Coy
Cum generezi asteptari realiste folosind segmentari de piata si personas
Cum generezi asteptari realiste folosind segmentari de piata si personas
Gabriel Curcudel
Web Apps Security
Web Apps Security
Victor Bucutea
Roberto Bicchierai - Defending web applications from attacks
Roberto Bicchierai - Defending web applications from attacks
Pietro Polsinelli
Intro to Web Application Security
Intro to Web Application Security
Rob Ragan
Web security 101
Web security 101
Kristaps K笛lis
Websec
Websec
Kristaps K笛lis
Web Security
Web Security
Gerald Villorente
2009 Barcamp Nashville Web Security 101
2009 Barcamp Nashville Web Security 101
brian_dailey
How to secure web applications
How to secure web applications
Mohammed A. Imran
Cum s creti v但nzrile online
Cum s creti v但nzrile online
Gabriel Curcudel
Local search 2013 Romania
Local search 2013 Romania
Gabriel Curcudel
Competitive link analysis si link management
Competitive link analysis si link management
Gabriel Curcudel
Local search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM Days
Gabriel Curcudel
Link building Tecomm Cluj
Link building Tecomm Cluj
Gabriel Curcudel
Analiza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2parale
Gabriel Curcudel
Long tail - Krumel - IMTO Seo & Sem
Long tail - Krumel - IMTO Seo & Sem
Gabriel Curcudel
Lumea Seo Sem Ppc
Lumea Seo Sem Ppc
Gabriel Curcudel
SEO si SEM strategii pentru afaceri oline
SEO si SEM strategii pentru afaceri oline
Gabriel Curcudel
Prezentare IMTO - Krumel
Prezentare IMTO - Krumel
Gabriel Curcudel
Working for the client's clients
Working for the client's clients
Gabriel Curcudel
Seo Vs Copywriting
Seo Vs Copywriting
Gabriel Curcudel
Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009
Gabriel Curcudel
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Gabriel Curcudel

More Related Content

Similar to Prezentarea "Securitatea Aplicatiilor Online" de la ODO (8)

Web Apps Security
Web Apps Security
Victor Bucutea
Roberto Bicchierai - Defending web applications from attacks
Roberto Bicchierai - Defending web applications from attacks
Pietro Polsinelli
Intro to Web Application Security
Intro to Web Application Security
Rob Ragan
Web security 101
Web security 101
Kristaps K笛lis
Websec
Websec
Kristaps K笛lis
Web Security
Web Security
Gerald Villorente
2009 Barcamp Nashville Web Security 101
2009 Barcamp Nashville Web Security 101
brian_dailey
How to secure web applications
How to secure web applications
Mohammed A. Imran
Roberto Bicchierai - Defending web applications from attacks
Roberto Bicchierai - Defending web applications from attacks
Pietro Polsinelli
Intro to Web Application Security
Intro to Web Application Security
Rob Ragan
2009 Barcamp Nashville Web Security 101
2009 Barcamp Nashville Web Security 101
brian_dailey
How to secure web applications
How to secure web applications
Mohammed A. Imran

More from Gabriel Curcudel (20)

Cum s creti v但nzrile online
Cum s creti v但nzrile online
Gabriel Curcudel
Local search 2013 Romania
Local search 2013 Romania
Gabriel Curcudel
Competitive link analysis si link management
Competitive link analysis si link management
Gabriel Curcudel
Local search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM Days
Gabriel Curcudel
Link building Tecomm Cluj
Link building Tecomm Cluj
Gabriel Curcudel
Analiza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2parale
Gabriel Curcudel
Long tail - Krumel - IMTO Seo & Sem
Long tail - Krumel - IMTO Seo & Sem
Gabriel Curcudel
Lumea Seo Sem Ppc
Lumea Seo Sem Ppc
Gabriel Curcudel
SEO si SEM strategii pentru afaceri oline
SEO si SEM strategii pentru afaceri oline
Gabriel Curcudel
Prezentare IMTO - Krumel
Prezentare IMTO - Krumel
Gabriel Curcudel
Working for the client's clients
Working for the client's clients
Gabriel Curcudel
Seo Vs Copywriting
Seo Vs Copywriting
Gabriel Curcudel
Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009
Gabriel Curcudel
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Gabriel Curcudel
Google Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi Adwords
Gabriel Curcudel
Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?
Gabriel Curcudel
Cum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De Cautare
Gabriel Curcudel
Webdeveloper Ciprian Berescu
Webdeveloper Ciprian Berescu
Gabriel Curcudel
Mituri Despre Antreprenoriat
Mituri Despre Antreprenoriat
Gabriel Curcudel
Online Commercial Intention
Online Commercial Intention
Gabriel Curcudel
Cum s creti v但nzrile online
Cum s creti v但nzrile online
Gabriel Curcudel
Local search 2013 Romania
Local search 2013 Romania
Gabriel Curcudel
Competitive link analysis si link management
Competitive link analysis si link management
Gabriel Curcudel
Local search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM Days
Gabriel Curcudel
Link building Tecomm Cluj
Link building Tecomm Cluj
Gabriel Curcudel
Analiza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2parale
Gabriel Curcudel
Long tail - Krumel - IMTO Seo & Sem
Long tail - Krumel - IMTO Seo & Sem
Gabriel Curcudel
SEO si SEM strategii pentru afaceri oline
SEO si SEM strategii pentru afaceri oline
Gabriel Curcudel
Prezentare IMTO - Krumel
Prezentare IMTO - Krumel
Gabriel Curcudel
Working for the client's clients
Working for the client's clients
Gabriel Curcudel
Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009
Gabriel Curcudel
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Gabriel Curcudel
Google Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi Adwords
Gabriel Curcudel
Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?
Gabriel Curcudel
Cum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De Cautare
Gabriel Curcudel
Webdeveloper Ciprian Berescu
Webdeveloper Ciprian Berescu
Gabriel Curcudel
Mituri Despre Antreprenoriat
Mituri Despre Antreprenoriat
Gabriel Curcudel
Online Commercial Intention
Online Commercial Intention
Gabriel Curcudel
Ad

Recently uploaded (20)

FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Alliance
Python Conference Singapore - 19 Jun 2025
Python Conference Singapore - 19 Jun 2025
ninefyi
Enhance GitHub Copilot using MCP - Enterprise version.pdf
Enhance GitHub Copilot using MCP - Enterprise version.pdf
Nilesh Gule
Securing AI - There Is No Try, Only Do!.pdf
Securing AI - There Is No Try, Only Do!.pdf
Priyanka Aash
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Alliance
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Alliance
War_And_Cyber_3_Years_Of_Struggle_And_Lessons_For_Global_Security.pdf
War_And_Cyber_3_Years_Of_Struggle_And_Lessons_For_Global_Security.pdf
biswajitbanerjee38
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
Priyanka Aash
Crypto Super 500 - 14th Report - June2025.pdf
Crypto Super 500 - 14th Report - June2025.pdf
Stephen Perrenod
ReSTIR [DI]: Spatiotemporal reservoir resampling for real-time ray tracing ...
ReSTIR [DI]: Spatiotemporal reservoir resampling for real-time ray tracing ...
revolcs10
OpenACC and Open Hackathons Monthly Highlights June 2025
OpenACC and Open Hackathons Monthly Highlights June 2025
OpenACC
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Safe Software
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
ICT Frame Magazine Pvt. Ltd.
You are not excused! How to avoid security blind spots on the way to production
You are not excused! How to avoid security blind spots on the way to production
Michele Leroux Bustamante
The Future of Data, AI, and AR: Innovation Inspired by You.pdf
The Future of Data, AI, and AR: Innovation Inspired by You.pdf
Safe Software
10 Key Challenges for AI within the EU Data Protection Framework.pdf
10 Key Challenges for AI within the EU Data Protection Framework.pdf
Priyanka Aash
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Alliance
Techniques for Automatic Device Identification and Network Assignment.pdf
Techniques for Automatic Device Identification and Network Assignment.pdf
Priyanka Aash
The Future of Technology: 2025-2125 by Saikat Basu.pdf
The Future of Technology: 2025-2125 by Saikat Basu.pdf
Saikat Basu
"Database isolation: how we deal with hundreds of direct connections to the d...
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Alliance
Python Conference Singapore - 19 Jun 2025
Python Conference Singapore - 19 Jun 2025
ninefyi
Enhance GitHub Copilot using MCP - Enterprise version.pdf
Enhance GitHub Copilot using MCP - Enterprise version.pdf
Nilesh Gule
Securing AI - There Is No Try, Only Do!.pdf
Securing AI - There Is No Try, Only Do!.pdf
Priyanka Aash
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Alliance
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Alliance
War_And_Cyber_3_Years_Of_Struggle_And_Lessons_For_Global_Security.pdf
War_And_Cyber_3_Years_Of_Struggle_And_Lessons_For_Global_Security.pdf
biswajitbanerjee38
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
GenAI Opportunities and Challenges - Where 370 Enterprises Are Focusing Now.pdf
Priyanka Aash
Crypto Super 500 - 14th Report - June2025.pdf
Crypto Super 500 - 14th Report - June2025.pdf
Stephen Perrenod
ReSTIR [DI]: Spatiotemporal reservoir resampling for real-time ray tracing ...
ReSTIR [DI]: Spatiotemporal reservoir resampling for real-time ray tracing ...
revolcs10
OpenACC and Open Hackathons Monthly Highlights June 2025
OpenACC and Open Hackathons Monthly Highlights June 2025
OpenACC
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Improving Data Integrity: Synchronization between EAM and ArcGIS Utility Netw...
Safe Software
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
Information Security Response Team Nepal_npCERT_Vice_President_Sudan_Jha.pdf
ICT Frame Magazine Pvt. Ltd.
You are not excused! How to avoid security blind spots on the way to production
You are not excused! How to avoid security blind spots on the way to production
Michele Leroux Bustamante
The Future of Data, AI, and AR: Innovation Inspired by You.pdf
The Future of Data, AI, and AR: Innovation Inspired by You.pdf
Safe Software
10 Key Challenges for AI within the EU Data Protection Framework.pdf
10 Key Challenges for AI within the EU Data Protection Framework.pdf
Priyanka Aash
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Alliance
Techniques for Automatic Device Identification and Network Assignment.pdf
Techniques for Automatic Device Identification and Network Assignment.pdf
Priyanka Aash
The Future of Technology: 2025-2125 by Saikat Basu.pdf
The Future of Technology: 2025-2125 by Saikat Basu.pdf
Saikat Basu
"Database isolation: how we deal with hundreds of direct connections to the d...
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
Ad

Prezentarea "Securitatea Aplicatiilor Online" de la ODO