Assessing and Exploiting Web Applications with Samurai WTF.pdf

(1633 KB) Pobierz
Assessing and Exploiting
Web Applications with
S
amurai
WTF
Raul Siles
Founder & Senior Security Analyst
Taddong
Copyright 2009-2012 Justin Searle / Raul Siles - This work is licensed under the Creative Commons Attribution-ShareAlike 3.0 License
CC Attribution-ShareAlike
For more details, visit http://creativecommons.org/licenses/by-sa/3.0/
If you use these slides, please offer the course under a different name so people don't confuse it with our officially offered course.
Copyright 2009-2012 Justin Searle / Raul Siles - This work is licensed under the Creative Commons Attribution-ShareAlike 3.0 License
2
Course Contributors
Course Authors
Justin Searle - justin@utilisec.com - @meeas
Raul Siles - raul@taddong.com - @taddong
Course Sponsors
UtiliSec – http://www.utilisec.com
Secure Ideas L.L.C. – http://www.secureideas.net
Taddong S.L. – http://www.taddong.com
Copyright 2009-2012 Justin Searle / Raul Siles - This work is licensed under the Creative Commons Attribution-ShareAlike 3.0 License
3
Course Outline
Introduction to SamuraiWTF
Testing Methodology
Mapping Applications
Discovering Vulnerabilities
Exploiting Vulnerabilities
Student Challenge
Appendix Materials (time permitting)
Copyright 2009-2012 Justin Searle / Raul Siles - This work is licensed under the Creative Commons Attribution-ShareAlike 3.0 License
4
SamuraiWTF
• Live testing environment as a bootable DVD
• Based on Ubuntu Linux
• Over 100 tools, extensions, and scripts,
included:
w3af
BeEF
Burp Suite
OWASP ZAP
Grendel-Scan
Rat Proxy
DirBuster
CeWL
Sqlmap
Maltego CE
WebScarab
Nmap
Nikto
Metasploit
5
Copyright 2009-2012 Justin Searle / Raul Siles - This work is licensed under the Creative Commons Attribution-ShareAlike 3.0 License
Zgłoś jeśli naruszono regulamin