OWASP NZ SEP 2011 - Clickjacking for Shells.pdf
(
2777 KB
)
Pobierz
Clickjacking For Shells
OWASP Wellington, New Zealand Chapter Meeting
September 2011
PDF Version
Introductions
Hello Everybody
My name is Andrew Horton aka urbanadventurer
Security Consultant for Security-Assessment.com
Develop security tools
WhatWeb – Web scanner included in BackTrack
URLCrazy – Domain name typo squatting research
and more
Operate MorningStar Security News
You may have seen me giving presentations at Kiwicon
Videos Not Available
This PDF version of the Clickjacking For Shells
presentation does not include videos.
See the video version for demos
Agenda
What is clickjacking?
Clickjacking in the wild
Are web apps vulnerable to clickjacking?
WordPress clickjacking 0day
How to protect your webapp from clickjacking
What is Clickjacking?
You think you’re clicking on the
website you see but no… you’re really
clicking on an
invisible website
you
cannot see that’s right under your
mouse.
Clickjacking affects many browsers
and platforms
First published in 2008 by Jeremiah
Grossman and Robert ―Rsnake‖
Hansen
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
TROOPERS - UI Redressing Attacks on Android Devices.pdf
(8028 KB)
Unknown Tales of Web Applica1on Security.pdf
(8624 KB)
Clickjacking - Attacks and Defenses.pdf
(1088 KB)
Busting Frame Busting - A Study of Clickjacking Vulnerabilities on Popular Sites.pdf
(1015 KB)
A Solution for the Automated Detection of Clickjacking Attacks.pdf
(398 KB)
Inne foldery tego chomika:
Advanced
Attack
Basics
BlackHat
Defcon 24
Zgłoś jeśli
naruszono regulamin