OWASP安全测试指南解读1

in 网络安全 with 247 comments

前言

刚接触这方面,下面是在阅读相关知识时看到的一篇总结性的文章,很多东西没怎么看懂,就先记录下来了。算是对参考文献的阅读笔记吧。

OWASP

一个世界范围的致力于提高应用程序安全性的自由开源社区。

目的是使应用程序的安全性变得可视化

发布一个完整的测试框架,人们可以根据需要建立自己的测试程序。


测试任务——>测试报告

流程

开始web渗透测试——信息搜集——配置以及部署管理测试——身份鉴别管理测试

——认证测试——授权测试——会话管理测试——输入验证测试——错误处理测试

——密码学测试——业务逻辑测试——客户端测试——输出交付件,结束测试


1、收集信息(很关键,收集尽可能多的信息)

OSINT(公开来源情报)、子域名、应用程序入口、web服务器、应用程序框架等


2、配置以及部署管理测试

web环境:操作系统、web服务器、web容器、开发框架、编程语言等


3、身份鉴别管理测试

登录:身份、认证、授权

认证方式:密码、PIN、工卡、钥匙、指纹、虹膜、签名等

授权方式:DAC(自主访问控制)、MAC(强制访问控制)、RBAC(基于角色的访问控制)、ABAC(基于属性的访问控制)


4、认证测试

怎么证明你是你【狗头】,需要了解认证机制

5、授权测试

授权测试以会话为中心


6、会话管理测试

CSRF:Cross-site request forgery,跨站请求伪造,网站用户提交了未经授权的命令,通过跨站请求伪造,网站应用程序信任这些命令。

会话固定、会话退出、会话超时等等


7、输入验证测试

内容很多

8、错误处理测试

输入异常错误,进行测试。

9、密码学测试、业务逻辑测试、客户端测试

相对独立,可以独立测试


学习路线

  1. 网络安全、web安全的一些概念
  2. 单个漏洞角度学习
  3. 综合性的web资源
  4. 安全测试指南解读
多去实践

参考文档

  1. OWASP安全测试指南解读

学习资料

  1. OWASP官网
  2. owasp-skf单个漏洞讲解
  3. web-application-security-tools-resources综合性的web安全资源
  4. 安全测试指南-第四版中文版
Responses
  1. |Avoid any horizontal stripes if your weight is higher. This puts emphasis on how wide your body is, making it look even wider. Instead, pick a pattern that is linear or vertical which can make you look thinner.

    Reply
  2. }{There are nearly unlimited options available for hair accessories. Accessories for your hair include scrunchies in a myriad of colors and fabrics, headbands, elegant barrettes, and even clip-on hair extensions. Don't forget to include hair accessories. For instance, if you are going for a sporty look, match a ponytail holder to your track suit for a great look and practicality. Choose fancier hair accessories to match fancier outfits.

    Reply
  3. }{When you want to look slimmer, avoid stripes which run horizontally. These stripes will give the illusion of widening and this is not the look you want to achieve. Instead, wear a vertical stripe pattern that will make you look tall instead of wide.

    Reply
  4. |Wearing white after the end of summer used to be considered a huge fashion faux pas. Any color, as long as it is flattering, is appropriate. So, if it's white you want to wear, wear it proudly and ignore people who say you shouldn't. Most people don't even think about what time of year it is when regarding your outfit.

    Reply
  5. |Create your own special style. It is easy to dress like everyone else, but you should create a style all your own. You have to be comfortable with yourself in order to do this. Although once you decide to follow this path, you will notice the increase in compliments you receive.

    Reply
  6. |Sheer clothes are a good option, but only limited to certain types of events. Wearing clothing items that are sheer in private areas can make you appear trashy rather than classy.

    Reply
  7. |Moisturizing shampoos can help with frizzy hair, so look for that property listed on the bottle. These products help to shield the hair from outside moisture. It's also a good idea to steer away from a product that says it is "volumizing".

    Reply