Presentation is loading. Please wait.

Presentation is loading. Please wait.

Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.

Similar presentations


Presentation on theme: "Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP."— Presentation transcript:

1 Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP http://www.owasp.org OWASP UniversityChallenge OWASP AppSec-USA September 2011

2 OWASP The OWASP University Challenge Attack Defence

3 OWASP The OWASP University Challenge 3 Teams: Dakota State University University of North Carolina at Charlotte St. Cloud State University

4 OWASP Final Score:

5 OWASP Final Score:

6 OWASP Winner of the Attack part: St. Cloud State University Joshua Platz Jake Soenneker

7 OWASP 7 Web and Encryption Vulnerabilities  XSS – Easy and Hard Ways (plain-text vs ascii char)  Blocks Of Suspicious Encoding  (ASCII, Unescape, Reverse, HTML Markup)  Browser Agents  Faking Browser Identity  Executing Remote Code (rouge php shell script)  Client Side Vs. Server Side Authentication  Fake Images / Pages  Reference Locations  Hidden Elements

8 OWASP 8 Encryption Vulnerabilities  SSH Vulnerability  Cipher Analysis

9 OWASP Winner of the Defence part: University of North Carolina at Charlotte Joshua Schroeder Joel Kerr Chris Burke

10 OWASP Object Binding Systematic problem with MVC frameworks Fields are improperly interacting with objects DataBinder Class can be used as mitigation setAllowedFields Property allows whitelisting of parameters UNC Charlotte

11 OWASP Web Application Firewall Mod_JK Linking Apache to Tomcat Mod Security Identifies and denies XSS and SQL injection attacks 11 UNC Charlotte

12 OWASP Input Validation Identified problems with ASIDE Static Analysis Tool Provides mitigation suggestions Defense against XSS 12 UNC Charlotte


Download ppt "Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP."

Similar presentations


Ads by Google