'0x04 reference'에 해당되는 글 3건
- 2009.03.09 php fuzzing_auditing version 1
- 2009.02.28 TOP WEB 2.0 SECURITY THREATS
- 2009.02.26 Top Ten Web Hacking Techniques of 2008
0x04 reference2009. 3. 9. 15:27
0x04 reference2009. 2. 28. 18:11
출 처 : http://www.secure-enterprise20.org/files/Top%20Web%202%200%20Security%20Threats.pdf
메일링 읽다가 링크에 링크를 거쳐 읽게된 문서.
개방, 상호간의 대화를 지향하는 웹2.0 에서도 현재 알려진 취약점들이 공통으로 적용된다는 것을 말하고 있다.
상세한 설명보다는 취약점에 대한 가이드라인정도를 이야기 하고 있다.
식상할 수도 있지만(이런 거만한 인간같으니,, 글작성하는 사람을 생각하자..) 가볍게 한번쯤 꼭 읽어 두자.
// 계획, 산책, 삼선볶은밥, 라면, 차문뜯기, 엔초비에 사고침(훈형)
메일링 읽다가 링크에 링크를 거쳐 읽게된 문서.
개방, 상호간의 대화를 지향하는 웹2.0 에서도 현재 알려진 취약점들이 공통으로 적용된다는 것을 말하고 있다.
상세한 설명보다는 취약점에 대한 가이드라인정도를 이야기 하고 있다.
식상할 수도 있지만(이런 거만한 인간같으니,, 글작성하는 사람을 생각하자..) 가볍게 한번쯤 꼭 읽어 두자.
// 계획, 산책, 삼선볶은밥, 라면, 차문뜯기, 엔초비에 사고침(훈형)
0x04 reference2009. 2. 26. 10:02
출처 : http://jeremiahgrossman.blogspot.com/2009/02/top-ten-web-hacking-techniques-of-2008.html
1. GIFAR
(Billy Rios, Nathan McFeters, Rob Carter, and John Heasman)
2. Breaking Google Gears' Cross-Origin Communication Model
(Yair Amit)
3. Safari Carpet Bomb
(Nitesh Dhanjani)
4. Clickjacking / Videojacking
(Jeremiah Grossman and Robert Hansen)
5. A Different Opera
(Stefano Di Paola)
6. Abusing HTML 5 Structured Client-side Storage
(Alberto Trivero)
7. Cross-domain leaks of site logins via Authenticated CSS
(Chris Evans and Michal Zalewski)
8. Tunneling TCP over HTTP over SQL Injection
(Glenn Wilkinson, Marco Slaviero and Haroon Meer)
9. ActiveX Repurposing
(Haroon Meer)
10. Flash Parameter Injection
(Yuval Baror, Ayal Yogev, and Adi Sharabani)
참고자료
- CUPS Detection
- CSRFing the uTorrent plugin
- Clickjacking / Videojacking
- Bypassing URL Authentication and Authorization with HTTP Verb Tampering
- I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)
- Safari Carpet Bomb
- Flash clipboard Hijack
- Flash Internet Explorer security model bug
- Frame Injection Fun
- Free MacWorld Platinum Pass? Yes in 2008!
- Diminutive Worm, 161 byte Web Worm
- SNMP XSS Attack (1)
- Res Timing File Enumeration Without JavaScript in IE7.0
- Stealing Basic Auth with Persistent XSS
- Smuggling SMTP through open HTTP proxies
- Collecting Lots of Free 'Micro-Deposits'
- Using your browser URL history to estimate gender
- Cross-site File Upload Attacks
- Same Origin Bypassing Using Image Dimensions
- HTTP Proxies Bypass Firewalls
- Join a Religion Via CSRF
- Cross-domain leaks of site logins via Authenticated CSS
- JavaScript Global Namespace Pollution
- GIFAR
- HTML/CSS Injections - Primitive Malicious Code
- Hacking Intranets Through Web Interfaces
- Cookie Path Traversal
- Racing to downgrade users to cookie-less authentication
- MySQL and SQL Column Truncation Vulnerabilities
- Building Subversive File Sharing With Client Side Applications
- Firefox XML injection into parse of remote XML
- Firefox cross-domain information theft (simple text strings, some CSV)
- Firefox 2 and WebKit nightly cross-domain image theft
- Browser's Ghost Busters
- Exploiting XSS vulnerabilities on cookies
- Breaking Google Gears' Cross-Origin Communication Model
- Flash Parameter Injection
- Cross Environment Hopping
- Exploiting Logged Out XSS Vulnerabilities
- Exploiting CSRF Protected XSS
- ActiveX Repurposing, (1, 2)
- Tunneling tcp over http over sql-injection
- Arbitrary TCP over uploaded pages
- Local DoS on CUPS to a remote exploit via specially-crafted webpage (1)
- JavaScript Code Flow Manipulation
- Common localhost dns misconfiguration can lead to "same site" scripting
- Pulling system32 out over blind SQL Injection
- Dialog Spoofing - Firefox Basic Authentication
- Skype cross-zone scripting vulnerability
- Safari pwns Internet Explorer
- IE "Print Table of Links" Cross-Zone Scripting Vulnerability
- A different Opera
- Abusing HTML 5 Structured Client-side Storage
- SSID Script Injection
- DHCP Script Injection
- File Download Injection
- Navigation Hijacking (Frame/Tab Injection Attacks)
- UPnP Hacking via Flash
- Total surveillance made easy with VoIP phone
- Social Networks Evil Twin Attacks
- Recursive File Include DoS
- Multi-pass filters bypass
- Session Extending
- Code Execution via XSS (1)
- Redirector’s hell
- Persistent SQL Injection
- JSON Hijacking with UTF-7
- SQL Smuggling
- Abusing PHP Sockets (1, 2)
- CSRF on Novell GroupWise WebAccess