OWASP安全测试指南解读1

in 网络安全 with 249 comments

前言

刚接触这方面,下面是在阅读相关知识时看到的一篇总结性的文章,很多东西没怎么看懂,就先记录下来了。算是对参考文献的阅读笔记吧。

OWASP

一个世界范围的致力于提高应用程序安全性的自由开源社区。

目的是使应用程序的安全性变得可视化

发布一个完整的测试框架,人们可以根据需要建立自己的测试程序。


测试任务——>测试报告

流程

开始web渗透测试——信息搜集——配置以及部署管理测试——身份鉴别管理测试

——认证测试——授权测试——会话管理测试——输入验证测试——错误处理测试

——密码学测试——业务逻辑测试——客户端测试——输出交付件,结束测试


1、收集信息(很关键,收集尽可能多的信息)

OSINT(公开来源情报)、子域名、应用程序入口、web服务器、应用程序框架等


2、配置以及部署管理测试

web环境:操作系统、web服务器、web容器、开发框架、编程语言等


3、身份鉴别管理测试

登录:身份、认证、授权

认证方式:密码、PIN、工卡、钥匙、指纹、虹膜、签名等

授权方式:DAC(自主访问控制)、MAC(强制访问控制)、RBAC(基于角色的访问控制)、ABAC(基于属性的访问控制)


4、认证测试

怎么证明你是你【狗头】,需要了解认证机制

5、授权测试

授权测试以会话为中心


6、会话管理测试

CSRF:Cross-site request forgery,跨站请求伪造,网站用户提交了未经授权的命令,通过跨站请求伪造,网站应用程序信任这些命令。

会话固定、会话退出、会话超时等等


7、输入验证测试

内容很多

8、错误处理测试

输入异常错误,进行测试。

9、密码学测试、业务逻辑测试、客户端测试

相对独立,可以独立测试


学习路线

  1. 网络安全、web安全的一些概念
  2. 单个漏洞角度学习
  3. 综合性的web资源
  4. 安全测试指南解读
多去实践

参考文档

  1. OWASP安全测试指南解读

学习资料

  1. OWASP官网
  2. owasp-skf单个漏洞讲解
  3. web-application-security-tools-resources综合性的web安全资源
  4. 安全测试指南-第四版中文版
Responses / Cancel Reply
  1. |When wearing sheer clothes, make sure the sheer parts are in the right areas. Make sure that you remain classy at all times, and cover your private areas.

    Reply
  2. buy latanoprost online brand xeloda 500mg exelon 3mg pills

    Reply
  3. where can i buy enalapril enalapril 10mg drug purchase lactulose generic

    Reply
  4. order amoxicillin online uk

    Reply
  5. mestinon 60 mg cheap order generic feldene buy rizatriptan 10mg

    Reply
  6. Later, Rudolph's son Maurizio inherited control of Gucci. Since he was restrained by his father, he has become extravagant. On Christmas Day in 985, Maurizio pretended to be away from home on a business trip. The next day, he sent someone to send a divorce agreement to his wife, Patricia. An angry Patricia cursed: "I want to see him die with my own eyes!"

    Reply
  7. Previously we reported the "Reverse Gold buckle" Cheap Jordan 12 "Reverse Taxi"!

    Reply
  8. buy cheap generic diltiazem buy generic acyclovir online how to buy allopurinol

    Reply
  9. Thanks so much for giving everyone such a breathtaking opportunity to discover important secrets from this blog. It is always so sweet and stuffed with fun for me and my office colleagues to visit your website more than three times in a week to learn the newest guides you have. And indeed, I'm usually astounded with all the striking tricks served by you. Certain 4 areas in this article are in fact the most beneficial we have all ever had.

    Reply
  10. My spouse and i got very happy when Peter managed to conclude his homework via the precious recommendations he discovered using your web site. It is now and again perplexing to just be giving for free concepts that many most people might have been selling. So we discover we've got you to be grateful to for that. The illustrations you made, the easy blog navigation, the relationships you can help instill - it's got all unbelievable, and it's really making our son and our family recognize that that issue is satisfying, which is especially mandatory. Many thanks for the whole lot!

    Reply