Upgrade to Pro — share decks privately, control downloads, hide ads and more …

2015.04.02 從滲透測試談企業常見資安風險

DEVCORE
April 02, 2015

2015.04.02 從滲透測試談企業常見資安風險

2014.04.02 iThome 資安大會

DEVCORE

April 02, 2015
Tweet

More Decks by DEVCORE

Other Decks in Technology

Transcript

  1. ฎฯᦡᡂ⍮Ⱅ 29.9% 6.4% 9.6% 13.1% 15.1% 25.9% Cross-Site Scripting SQL

    Injection Business Logic Flaw Cross-Site Request Forgery Information Leakage Others
  2. ฎฯᦡᡂ⍮Ⱅ 08"415PQ 29.9% 6.4% 9.6% 13.1% 15.1% 25.9% 2013 A3

    2013 A1 Business Logic Flaw 2013 A8 2007 A6 Others
  3. *OGPSNBUJPO-FBLBHF Ø ࿜ࡻ㡩⋞⼮̍ܓ࿡㉐ḋ␹⭶ஂㅟ⯉㡦ௐ╿≕⊶ᖤሪ⳽⭠ធᣩ ት⋣⃳ʲ Ø ബ⬔᭱ᝄ Ø ػ੉ᾋធᣩന⢬ஞᾋơធᣩท٪ṕㄻ Ø ㅟ⯉⭠ິធᣩ⋣⃳⁰෇ⶦนơធᣩ⾠Ձػ੉ᾋ

    Ø ធᣩ͵ᓹ≕⊶ơ'SBNFXPSL㐦ِࣘᬝ፭ Ø ё̶ᗃᐲធᣩ⋣⃳Ꮜᕀơػ੉ᾋ Ø ข㏡㡩ʵʬஂፒ⃯أ㐹㋵㡦͡⊛ٸӱ̝ො㞾ዏข㏡٩য়٩௑
  4. ⼶༚໏ܠ㏄⃥ Ø ࢢӨ⋣ḑ≕⊶୹өᜥፒ㊣‭ᖤ՟ ➡ ท٪ӑᣜٵ₇*OKFDUJPO㡦㉐ⵖ৙TFSWJDF GUQ STZOD  Ø ท٪ͦ⏀ৡ਒ᮯ

    ➡ IUUQEFWDPSFBENJO ➡ IUUQBENJOEFWDPSF Ø ท٪ٕϫ຃ٽ୕͹⍍ဪʵ՚˯ڒ ➡ (PPHMF)BDLJOH
  5. ⑓ΐΦ໏⾱⺼ᙜؕ Ø Ṍჾ≕⊶ ➡ *%4ơ*14 ➡ ឪぞ ➡ ᗃᐲᵐֽ Ø

    -PH ➡ ϑୖ።㊶ৡἈ㡢යⱬ╾௓ϑୖ؍ൖ㡣 ➡ ፫ᵐࢩё̶