InformationExtractionArtofTestingNetworkPeripheralDevices.pdf

(1982 KB) Pobierz
OWASP AppSec
Brazil 2010, Campinas, SP
The OWASP Foundation
http://www.owasp.org
Information Extraction
Art of Testing Network Peripheral Devices
Aditya K Sood , SecNiche Security
(adi_ks@secniche.org)
Mauro Risonho de Paula Assumpção
(firebits@backtrack.com.br)
The OWASP Foundation
http://www.owasp.org
Disclaimer
All the views solely based on the work conducted by
SecNiche Security.
(C) SecNiche Security | http://www.secniche.org
Content should be used with the permission of SecNiche
2
Agenda
Why Information Gathering?
Information Gathering Patterns
Web Network Devices – Case Studies
Proxy and Anonoymous Services
Bad Design Practices
Free Web
Conclusion
3
Information Gathering – First Critical Step
4
Information Gathering Facets on Web
Complex web networks
Peripheral network devices securing web
Ofcourse, World Wide Web is random
5
Zgłoś jeśli naruszono regulamin