-
14
pages
-
English
-
Documents
Description
ISSNSM — International Summer School on Network and Service Management 2nd ISSNSM’s Tutorial onHacking Web2(Tutorial T1)Speaker:Radu StateJune 2, 2008Radu State Ph.D. The MADYNES Research Team LORIA – INRIA Lorraine 615, rue du Jardin Botanique 54602 Villers-lès-Nancy France Radu.State@loria.fr Emanics Summer School, 2008 Zurich - 1 - What is Web Hacking ? Penetrate the network using web applications and servers How is this done 1. Exploit vulnerable servers (SSL buffer overflows, directory traversal, etc) 2. Exploit weak configurations 3. Exploit web applications Emanics Summer School, 2008 Zurich - 2 - Security threats and vulnerabilities • What is Security ? – “Security is a process not a product”, Bruce Schneier, – “Maintaining an acceptable level of perceived risk”, Richard Bejtlich. • What is a threat ? – A threat is an external security issue represented by a natural or man-made attack • What is a vulnerability ? – a specific degree of weakness of an individual computer or network exposed to the influence of a threat• What is risk ? – A risk is the degree of probability that a disaster will occur in light of the existing conditions, and the degree of vulnerability or weakness present in the system. The key difference between a threat and a risk is that a threat is related to the potential occurrence of a security issue, whereas a risk is the probability of an incident occurring based on the degree of exposure ...
-
Publié par
-
Langue
English