Link
Embed
Share
Beginning
This slide
Copy link URL
Copy link URL
Copy iframe embed code
Copy iframe embed code
Copy javascript embed code
Copy javascript embed code
Share
Tweet
Share
Tweet
Slide 1
Slide 1 text
Computer Science E-1 Lecture 6: Security
Slide 2
Slide 2 text
http://youtu.be/H542nLTTbu0
Slide 3
Slide 3 text
http://bing.com
Slide 4
Slide 4 text
http://vimeo.com/blog/post:564
Slide 5
Slide 5 text
Security
Slide 6
Slide 6 text
Authentication
Slide 7
Slide 7 text
Cookies
Slide 8
Slide 8 text
Sessions
Slide 9
Slide 9 text
GET /home.php HTTP/1.1 Host: www.facebook.com Cookie: PHPSESSID=5153d29ed84c4
Slide 10
Slide 10 text
GET /home.php HTTP/1.1 Host: www.facebook.com Cookie: PHPSESSID=5153d29ed84c4
Slide 11
Slide 11 text
Session Hijacking
Slide 12
Slide 12 text
No content
Slide 13
Slide 13 text
HTTPS
Slide 14
Slide 14 text
Cryptography
Slide 15
Slide 15 text
GET /home.php HTTP/1.1 Host: www.facebook.com Encrypt ehosn9745t987gnlkjab 7@5uejfnjasdbfxb98@#
Slide 16
Slide 16 text
GET /home.php HTTP/1.1 Host: www.facebook.com Encrypt ehosn9745t987gnlkjab 7@5uejfnjasdbfxb98@# ehosn9745t987gnlkjab 7@5uejfnjasdbfxb98@# GET /home.php HTTP/1.1 Host: www.facebook.com Decrypt
Slide 17
Slide 17 text
Wi-Fi Security
Slide 18
Slide 18 text
WEP, WPA, WPA2
Slide 19
Slide 19 text
CSRF
Slide 20
Slide 20 text
https://bank.com/money/transfer? to=67890&amount=100
Slide 21
Slide 21 text
No content
Slide 22
Slide 22 text
Ka-Boom.
Slide 23
Slide 23 text
https://bank.com/money/transfer? to=67890&amount=100& token=8549ba93417cdef85
Slide 24
Slide 24 text
Slide 25
Slide 25 text
http://cse1.net/lecture6
Slide 26
Slide 26 text
XSS
Slide 27
Slide 27 text
Tommy
Slide 28
Slide 28 text
No content
Slide 29
Slide 29 text
Ka-Boom.
Slide 30
Slide 30 text
http://cse1.net/lecture6
Slide 31
Slide 31 text
Databases
Slide 32
Slide 32 text
Name DOB Color Preference Shocked Cat 3/17/2010 white indoor Grumpy Cat 4/4/2012 white indoor Keyboard Cat 1/1/1984 orange outdoor
Slide 33
Slide 33 text
SQL
Slide 34
Slide 34 text
SELECT name FROM cats
Slide 35
Slide 35 text
SELECT * from cats WHERE preference = ‘indoor’
Slide 36
Slide 36 text
INSERT INTO cats (name, dob, color, preference) VALUES ('Maru', '2008-06-01', 'gray', 'indoor')
Slide 37
Slide 37 text
UPDATE cats SET name = ‘shocked’ WHERE name = ‘Maru’
Slide 38
Slide 38 text
DELETE FROM cats WHERE name = ‘Maru’
Slide 39
Slide 39 text
CRUD
Slide 40
Slide 40 text
Create Read Update Delete
Slide 41
Slide 41 text
INSERT SELECT UPDATE DELETE
Slide 42
Slide 42 text
SELECT * FROM profiles WHERE username = ‘zuck’
Slide 43
Slide 43 text
I would like __ cheeseburgers cooked ____ and topped with ________.
Slide 44
Slide 44 text
I would like 2 cheeseburgers cooked medium-well and topped with lettuce.
Slide 45
Slide 45 text
I would like 2 cheeseburgers cooked and then thrown at the nearest customer’s head and topped with lettuce.
Slide 46
Slide 46 text
Injection
Slide 47
Slide 47 text
SELECT * FROM profiles WHERE username = ‘______’
Slide 48
Slide 48 text
‘ OR ‘1’ = ‘1
Slide 49
Slide 49 text
SELECT * FROM profiles WHERE username = ‘’ OR ‘1’ = ‘1’
Slide 50
Slide 50 text
Ka-Boom.
Slide 51
Slide 51 text
Authentication
Slide 52
Slide 52 text
SELECT * FROM users WHERE username = ‘_____’ AND password = ‘_____’
Slide 53
Slide 53 text
SELECT * FROM users WHERE username = ‘rj’ AND password = ‘’ OR ‘1’ = ‘1’
Slide 54
Slide 54 text
Ka-Boom.
Slide 55
Slide 55 text
’; DELETE FROM profiles; --
Slide 56
Slide 56 text
SELECT * FROM profiles WHERE username = ‘’; DELETE FROM profiles; --’
Slide 57
Slide 57 text
No content
Slide 58
Slide 58 text
Sanitizing Input
Slide 59
Slide 59 text
SELECT * FROM profiles WHERE username = '\' OR \'1\' = \'1'
Slide 60
Slide 60 text
Permissions
Slide 61
Slide 61 text
http://cse1.net/lecture6
Slide 62
Slide 62 text
Encrypting Text
Slide 63
Slide 63 text
Caesar Cipher
Slide 64
Slide 64 text
ABCDEFGHIJKLMNOPQRSTUVWXYZ NOPQRSTUVWXYZABCDEFGHIJKLM
Slide 65
Slide 65 text
ROT13
Slide 66
Slide 66 text
banana
Slide 67
Slide 67 text
onanan
Slide 68
Slide 68 text
Brute-Force Attack
Slide 69
Slide 69 text
ROT26
Slide 70
Slide 70 text
Vigenère Cipher
Slide 71
Slide 71 text
banana + 246246
Slide 72
Slide 72 text
banana + 246246 detcrg
Slide 73
Slide 73 text
banana + cegceg detcrg
Slide 74
Slide 74 text
Plaintext: computer Key: benrj
Slide 75
Slide 75 text
computer + benrjben
Slide 76
Slide 76 text
computer + benrjben dszgduie
Slide 77
Slide 77 text
Symmetric-Key Cryptography
Slide 78
Slide 78 text
No content
Slide 79
Slide 79 text
Asymmetric-Key Cryptography
Slide 80
Slide 80 text
Public/Private Keys
Slide 81
Slide 81 text
No content
Slide 82
Slide 82 text
Trapdoor One-Way Function
Slide 83
Slide 83 text
2459 * 8863 = 21794117
Slide 84
Slide 84 text
Factor 21794117
Slide 85
Slide 85 text
RSA
Slide 86
Slide 86 text
Diffie-Hellman
Slide 87
Slide 87 text
Computer Science E-1 Lecture 6: Security