OWASP安全测试指南解读1

in 网络安全 with 247 comments

前言

刚接触这方面,下面是在阅读相关知识时看到的一篇总结性的文章,很多东西没怎么看懂,就先记录下来了。算是对参考文献的阅读笔记吧。

OWASP

一个世界范围的致力于提高应用程序安全性的自由开源社区。

目的是使应用程序的安全性变得可视化

发布一个完整的测试框架,人们可以根据需要建立自己的测试程序。


测试任务——>测试报告

流程

开始web渗透测试——信息搜集——配置以及部署管理测试——身份鉴别管理测试

——认证测试——授权测试——会话管理测试——输入验证测试——错误处理测试

——密码学测试——业务逻辑测试——客户端测试——输出交付件,结束测试


1、收集信息(很关键,收集尽可能多的信息)

OSINT(公开来源情报)、子域名、应用程序入口、web服务器、应用程序框架等


2、配置以及部署管理测试

web环境:操作系统、web服务器、web容器、开发框架、编程语言等


3、身份鉴别管理测试

登录:身份、认证、授权

认证方式:密码、PIN、工卡、钥匙、指纹、虹膜、签名等

授权方式:DAC(自主访问控制)、MAC(强制访问控制)、RBAC(基于角色的访问控制)、ABAC(基于属性的访问控制)


4、认证测试

怎么证明你是你【狗头】,需要了解认证机制

5、授权测试

授权测试以会话为中心


6、会话管理测试

CSRF:Cross-site request forgery,跨站请求伪造,网站用户提交了未经授权的命令,通过跨站请求伪造,网站应用程序信任这些命令。

会话固定、会话退出、会话超时等等


7、输入验证测试

内容很多

8、错误处理测试

输入异常错误,进行测试。

9、密码学测试、业务逻辑测试、客户端测试

相对独立,可以独立测试


学习路线

  1. 网络安全、web安全的一些概念
  2. 单个漏洞角度学习
  3. 综合性的web资源
  4. 安全测试指南解读
多去实践

参考文档

  1. OWASP安全测试指南解读

学习资料

  1. OWASP官网
  2. owasp-skf单个漏洞讲解
  3. web-application-security-tools-resources综合性的web安全资源
  4. 安全测试指南-第四版中文版
Responses
  1. cheap lanoxin cost digoxin 250mg buy molnunat generic

    Reply
  2. |Find conditioner that can help you with your hair if it frizzes. This will put a protective layer over the cuticle of your hair, keeping it from taking in too much moisture. Be sure to stay away from "volumizing" products too since they have wheat and rice in them.

    Reply
  3. |Do not strive for perfection in fashion. Nothing in the world is perfect. Also, if you attempt perfection, you may look like you are investing too much time and effort into the process. Some of the most successful fashion models have had at least one flaw, such as a long forehead or a gap between the teeth.

    Reply
  4. Thank you for each of your efforts on this site. Debby takes pleasure in participating in investigation and it's really easy to understand why. Many of us hear all relating to the powerful form you render invaluable solutions through this website and as well boost contribution from website visitors about this subject plus our girl is without a doubt understanding so much. Enjoy the rest of the year. You're the one doing a dazzling job.

    Reply
  5. diamox brand order imuran 25mg sale order imuran 50mg generic

    Reply
  6. buy coreg 25mg generic brand carvedilol aralen usa

    Reply
  7. I want to voice my appreciation for your kindness supporting people that have the need for help with your situation. Your special dedication to passing the solution all through had been extremely beneficial and have consistently allowed many people like me to arrive at their objectives. The interesting hints and tips denotes so much to me and a whole lot more to my colleagues. Many thanks; from all of us.

    Reply
  8. A lot of thanks for every one of your work on this web page. My mum loves making time for internet research and it is easy to understand why. We all notice all of the compelling mode you offer reliable tricks via this web blog and even cause participation from some other people on the point and our own princess is certainly discovering a whole lot. Take pleasure in the remaining portion of the new year. You have been performing a stunning job.

    Reply
  9. I am glad for commenting to make you understand what a magnificent discovery our princess obtained using yuor web blog. She mastered a wide variety of pieces, with the inclusion of what it's like to have an excellent coaching mood to get folks really easily thoroughly grasp a number of tricky subject matter. You truly surpassed visitors' expectations. Thank you for churning out the practical, trusted, revealing and also cool guidance on this topic to Gloria.

    Reply
  10. mesalamine 400mg pills azelastine for sale avapro sale

    Reply