Главная
Study mode:
on
1
Intro
2
Break Down
3
Collecting data
4
Trend data sets
5
Attacks!
6
Specific attacks against software
7
Life-cycle of an exploit
8
Theory about this trend...
9
PHP-CGI remote code execution
10
Attack Response
11
Attack sources
12
A little about incident response
13
Response breakdown
14
Standard approach
15
Auditing nitty gritty
16
File System Monitoring
17
Using find to cleanup
18
Attacker Motivation
19
Example.htaccess infection
20
Registrars
21
IP address
22
Backdoor evolution
23
Collection
24
Getting backdoors from attack logs
25
Dead Simple
26
Base64 decode
27
Regex revenge
28
Variables as functions
29
Backdoor Conclusions
30
Further Reading
Description:
Learn about advanced web application security techniques in this 42-minute conference talk from BSides Las Vegas 2012. Explore the lifecycle of exploits, specific attacks against software, and PHP-CGI remote code execution. Dive into attack response strategies, incident handling, and auditing practices, including file system monitoring and cleanup techniques. Examine attacker motivations, backdoor evolution, and methods for detecting and analyzing malicious code. Gain insights into .htaccess infections, IP address tracking, and advanced backdoor techniques such as variable function calls. Enhance your web security knowledge with practical examples and recommendations for further reading.

Max Level Web App Security - Attacks, Exploits, and Response Strategies

Add to list