Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Vulnerabilidades em sistemas web
Search
Daniel Romero
November 01, 2012
Programming
81
0
Share
Vulnerabilidades em sistemas web
Algumas das vulnerabilidades mais exploradas em aplicações web.
Daniel Romero
November 01, 2012
More Decks by Daniel Romero
See All by Daniel Romero
Segurança on Rails
infoslack
0
120
Other Decks in Programming
See All in Programming
LLM Plugin for Node-REDの利用方法と開発について
404background
0
130
3Dシーンの圧縮
fadis
1
460
These Five Tricks Can Make Your Apps Greener, Cheaper, & Nicer
hollycummins
0
240
TypeSpec で繋ぐ複数プロダクトの型安全
maroon8021
1
260
Composerを使ったサプライチェーン攻撃の様子を眺めてみる #phpstudy
o0h
PRO
2
190
AI 時代のソフトウェア設計の学び方
masuda220
PRO
28
11k
AIチームを指揮するOSS「TAKT」活用術 / How to Use “TAKT,” an OSS Tool for Orchestrating AI Teams
nrslib
6
740
Augmenting AI with the Power of Jakarta EE
ivargrimstad
0
330
net-httpのHTTP/2対応について
naruse
0
320
さぁV100、メモリをお食べ・・・
nilpe
0
110
Transactional Change Stream Processing With Debezium and Apache Flink
gunnarmorling
1
140
肥大化するレガシーコードに立ち向かうためのインターフェース分離と依存の逆転 / JJUG CCC 2026 Spring
hirokunimaeta
0
160
Featured
See All Featured
Technical Leadership for Architectural Decision Making
baasie
3
380
Heart Work Chapter 1 - Part 1
lfama
PRO
7
36k
Joys of Absence: A Defence of Solitary Play
codingconduct
1
380
Into the Great Unknown - MozCon
thekraken
41
2.5k
<Decoding/> the Language of Devs - We Love SEO 2024
nikkihalliwell
1
230
[RailsConf 2023] Rails as a piece of cake
palkan
59
6.6k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
Agile that works and the tools we love
rasmusluckow
331
21k
How to optimise 3,500 product descriptions for ecommerce in one day using ChatGPT
katarinadahlin
PRO
1
3.6k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
35
2.5k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
210
Git: the NoSQL Database
bkeepers
PRO
432
67k
Transcript
Vulnerabilidades em sistemas web
Primeiros passos • Vulnerabilidades • Técnicas • Ferramentas • OWASP
• SDL
Vulnerabilidades mais conhecidas • Injection • XSS • DdoS •
Top 10 - https://www.owasp.org/index.php/Top_10_2010-Main
SQL Injection • https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet • http://www.unixwiz.net/techtips/sql-injection.html
XSS • https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet • http://hack.us/
DDos • http://ha.ckers.org/slowloris/
Ferramentas • http://sqlmap.org/ - GitHub • http://www.metasploit.com/ - GitHub •
http://arachni-scanner.com/ - GitHub • http://brakemanscanner.org/ - GitHub • http://www.openvas.org/
Prática, hora dos testes
None
Daniel Romero
[email protected]
@infolslack