Download presentation
Presentation is loading. Please wait.
Published byJonas Simon Rose Modified over 9 years ago
1
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP http://www.owasp.org OWASP UniversityChallenge OWASP AppSec-USA September 2011
2
OWASP The OWASP University Challenge Attack Defence
3
OWASP The OWASP University Challenge 3 Teams: Dakota State University University of North Carolina at Charlotte St. Cloud State University
4
OWASP Final Score:
5
OWASP Final Score:
6
OWASP Winner of the Attack part: St. Cloud State University Joshua Platz Jake Soenneker
7
OWASP 7 Web and Encryption Vulnerabilities XSS – Easy and Hard Ways (plain-text vs ascii char) Blocks Of Suspicious Encoding (ASCII, Unescape, Reverse, HTML Markup) Browser Agents Faking Browser Identity Executing Remote Code (rouge php shell script) Client Side Vs. Server Side Authentication Fake Images / Pages Reference Locations Hidden Elements
8
OWASP 8 Encryption Vulnerabilities SSH Vulnerability Cipher Analysis
9
OWASP Winner of the Defence part: University of North Carolina at Charlotte Joshua Schroeder Joel Kerr Chris Burke
10
OWASP Object Binding Systematic problem with MVC frameworks Fields are improperly interacting with objects DataBinder Class can be used as mitigation setAllowedFields Property allows whitelisting of parameters UNC Charlotte
11
OWASP Web Application Firewall Mod_JK Linking Apache to Tomcat Mod Security Identifies and denies XSS and SQL injection attacks 11 UNC Charlotte
12
OWASP Input Validation Identified problems with ASIDE Static Analysis Tool Provides mitigation suggestions Defense against XSS 12 UNC Charlotte
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.