Ethical Hacking at MPICT - PowerPoint PPT Presentation

About This Presentation
Title:

Ethical Hacking at MPICT

Description:

Almost every Web site with a login is vulnerable. sslstrip. HTTP sites with HTTPS buttons like Facebook are vulnerable. Cross-Site Request Forgery (XSRF) ... – PowerPoint PPT presentation

Number of Views:176
Avg rating:3.0/5.0
Slides: 11
Provided by: samsc
Category:

less

Transcript and Presenter's Notes

Title: Ethical Hacking at MPICT


1
Ethical Hackingat MPICT
2
Two Attacks
  • Cross-Site Request Forgery
  • Almost every Web site with a login is vulnerable
  • sslstrip
  • HTTP sites with HTTPS buttons like Facebook are
    vulnerable

3
Cross-Site Request Forgery (XSRF)
4
Web-based Email
To Internet
Router
AttackerSniffingTraffic
TargetUsingEmail
5
Cross-Site Request Forgery (XSRF)
  • Gmail sends the password through a secure HTTPS
    connection
  • That cannot be captured by the attacker
  • But the cookie identifying the user is sent in
    the clearwith HTTP
  • That can easily be captured by the attacker
  • The attacker gets into your account without
    learning your password

6
Demonstration
7
sslstrip
8
The Problem
  • HTTP Page with an HTTPS Logon Button

9
Proxy Changes HTTPS to HTTP
To Internet
HTTPS
Attacker Evil Proxyin the Middle
HTTP
TargetUsingFacebook
10
Demonstration
Write a Comment
User Comments (0)
About PowerShow.com