Upgrade to Pro — share decks privately, control downloads, hide ads and more …

2015.04.02 從滲透測試談企業常見資安風險

Avatar for DEVCORE DEVCORE
April 02, 2015

2015.04.02 從滲透測試談企業常見資安風險

2014.04.02 iThome 資安大會

Avatar for DEVCORE

DEVCORE

April 02, 2015
Tweet

More Decks by DEVCORE

Other Decks in Technology

Transcript

  1. ฎฯᦡᡂ⍮Ⱅ 29.9% 6.4% 9.6% 13.1% 15.1% 25.9% Cross-Site Scripting SQL

    Injection Business Logic Flaw Cross-Site Request Forgery Information Leakage Others
  2. ฎฯᦡᡂ⍮Ⱅ 08"415PQ 29.9% 6.4% 9.6% 13.1% 15.1% 25.9% 2013 A3

    2013 A1 Business Logic Flaw 2013 A8 2007 A6 Others
  3. *OGPSNBUJPO-FBLBHF Ø ࿜ࡻ㡩⋞⼮̍ܓ࿡㉐ḋ␹⭶ஂㅟ⯉㡦ௐ╿≕⊶ᖤሪ⳽⭠ធᣩ ት⋣⃳ʲ Ø ബ⬔᭱ᝄ Ø ػ੉ᾋធᣩന⢬ஞᾋơធᣩท٪ṕㄻ Ø ㅟ⯉⭠ິធᣩ⋣⃳⁰෇ⶦนơធᣩ⾠Ձػ੉ᾋ

    Ø ធᣩ͵ᓹ≕⊶ơ'SBNFXPSL㐦ِࣘᬝ፭ Ø ё̶ᗃᐲធᣩ⋣⃳Ꮜᕀơػ੉ᾋ Ø ข㏡㡩ʵʬஂፒ⃯أ㐹㋵㡦͡⊛ٸӱ̝ො㞾ዏข㏡٩য়٩௑
  4. ⼶༚໏ܠ㏄⃥ Ø ࢢӨ⋣ḑ≕⊶୹өᜥፒ㊣‭ᖤ՟ ➡ ท٪ӑᣜٵ₇*OKFDUJPO㡦㉐ⵖ৙TFSWJDF GUQ STZOD  Ø ท٪ͦ⏀ৡ਒ᮯ

    ➡ IUUQEFWDPSFBENJO ➡ IUUQBENJOEFWDPSF Ø ท٪ٕϫ຃ٽ୕͹⍍ဪʵ՚˯ڒ ➡ (PPHMF)BDLJOH
  5. ⑓ΐΦ໏⾱⺼ᙜؕ Ø Ṍჾ≕⊶ ➡ *%4ơ*14 ➡ ឪぞ ➡ ᗃᐲᵐֽ Ø

    -PH ➡ ϑୖ።㊶ৡἈ㡢යⱬ╾௓ϑୖ؍ൖ㡣 ➡ ፫ᵐࢩё̶