OWASP安全测试指南解读1

in 网络安全 with 247 comments

前言

刚接触这方面,下面是在阅读相关知识时看到的一篇总结性的文章,很多东西没怎么看懂,就先记录下来了。算是对参考文献的阅读笔记吧。

OWASP

一个世界范围的致力于提高应用程序安全性的自由开源社区。

目的是使应用程序的安全性变得可视化

发布一个完整的测试框架,人们可以根据需要建立自己的测试程序。


测试任务——>测试报告

流程

开始web渗透测试——信息搜集——配置以及部署管理测试——身份鉴别管理测试

——认证测试——授权测试——会话管理测试——输入验证测试——错误处理测试

——密码学测试——业务逻辑测试——客户端测试——输出交付件,结束测试


1、收集信息(很关键,收集尽可能多的信息)

OSINT(公开来源情报)、子域名、应用程序入口、web服务器、应用程序框架等


2、配置以及部署管理测试

web环境:操作系统、web服务器、web容器、开发框架、编程语言等


3、身份鉴别管理测试

登录:身份、认证、授权

认证方式:密码、PIN、工卡、钥匙、指纹、虹膜、签名等

授权方式:DAC(自主访问控制)、MAC(强制访问控制)、RBAC(基于角色的访问控制)、ABAC(基于属性的访问控制)


4、认证测试

怎么证明你是你【狗头】,需要了解认证机制

5、授权测试

授权测试以会话为中心


6、会话管理测试

CSRF:Cross-site request forgery,跨站请求伪造,网站用户提交了未经授权的命令,通过跨站请求伪造,网站应用程序信任这些命令。

会话固定、会话退出、会话超时等等


7、输入验证测试

内容很多

8、错误处理测试

输入异常错误,进行测试。

9、密码学测试、业务逻辑测试、客户端测试

相对独立,可以独立测试


学习路线

  1. 网络安全、web安全的一些概念
  2. 单个漏洞角度学习
  3. 综合性的web资源
  4. 安全测试指南解读
多去实践

参考文档

  1. OWASP安全测试指南解读

学习资料

  1. OWASP官网
  2. owasp-skf单个漏洞讲解
  3. web-application-security-tools-resources综合性的web安全资源
  4. 安全测试指南-第四版中文版
Responses
  1. I simply wished to appreciate you again. I do not know the things that I could possibly have accomplished in the absence of these hints documented by you regarding this concern. Completely was an absolute horrifying condition for me, nevertheless viewing a new professional strategy you managed the issue forced me to weep over joy. I am happy for your assistance and then believe you recognize what an amazing job you have been getting into educating most people using your blog post. I am certain you haven't come across all of us.

    Reply
  2. I needed to put you that little observation to say thank you again over the fantastic advice you've discussed here. It was quite tremendously generous of you to present unreservedly what some people would have supplied for an e book to get some cash for themselves, chiefly seeing that you might well have done it if you ever wanted. Those points additionally worked like a easy way to fully grasp someone else have the same dream just as mine to understand way more concerning this problem. I am sure there are many more fun sessions up front for people who looked over your site.

    Reply
  3. I'm writing to let you understand what a awesome encounter my wife's princess enjoyed using your blog. She even learned plenty of pieces, which included what it is like to possess a very effective giving nature to have other individuals without hassle know just exactly several impossible topics. You actually surpassed our desires. Many thanks for offering the warm and friendly, trustworthy, informative and fun thoughts on this topic to Lizeth.

    Reply
  4. Read reviews and was a little hesitant since I had already inputted my order. or maybe but thank god, I had no issues. much like the received item in a timely matter, they are in new condition. you ultimately choose so happy I made the purchase. Will be definitely be purchasing again.
    cheap louis vuitton online https://www.louisvuittonsoutletonline.com/

    Reply
  5. Read reviews and was a little hesitant since I had already inputted my order. nor but thank god, I had no issues. just like received item in a timely matter, they are in new condition. either way so happy I made the purchase. Will be definitely be purchasing again.
    cheap jordans https://www.realjordansretro.com/

    Reply
  6. Read reviews and was a little hesitant since I had already inputted my order. potentially but thank god, I had no issues. such as the received item in a timely matter, they are in new condition. an invaluable so happy I made the purchase. Will be definitely be purchasing again.
    cheap jordan shoes https://www.realjordansretro.com/

    Reply
  7. Thanks a lot for giving everyone a very superb opportunity to check tips from this web site. It's usually so pleasurable and as well , stuffed with a lot of fun for me personally and my office peers to search the blog minimum thrice a week to read the fresh secrets you have. Of course, I'm always impressed with the extraordinary guidelines you serve. Some two ideas in this post are absolutely the simplest we have all ever had.

    Reply
  8. cialis 5 mg buy cialis 10mg generic buy ed pills fda

    Reply
  9. order generic tadalafil 20mg purchase cialis pills ed pills gnc

    Reply
  10. cialis ca cialis cost mens erection pills

    Reply