disclosing vulnerabilities for fun and profit

29
Disclosing Vulnerabilities FOR FUN & PROFIT Nikhil.P.Kulkarni www.twitter.com/nikchillz

Upload: nu-the-open-security-community

Post on 18-Nov-2014

1.173 views

Category:

Education


2 download

DESCRIPTION

null Bangalore Chapter, January 2013 Meet

TRANSCRIPT

Page 1: Disclosing Vulnerabilities for Fun and Profit

Disclosing Vulnerabilities

FOR FUN & PROFIT

Nikhil.P.Kulkarni

www.twitter.com/nikchillz

Page 2: Disclosing Vulnerabilities for Fun and Profit

Nikhil Kulkarni

A 21yr old Tech Enthusiast.

A Blogger, Web Designer, Graphical

Designer

Mainly into Web App Testing

(aka Intrud3r)

facebook.com/nikchillz

twitter.com/nikchillz

Page 3: Disclosing Vulnerabilities for Fun and Profit
Page 4: Disclosing Vulnerabilities for Fun and Profit
Page 5: Disclosing Vulnerabilities for Fun and Profit

File Inclusion BUG

Page 6: Disclosing Vulnerabilities for Fun and Profit

VULNERABILITY

DISCLOSURE

FULL DISCLOSURE

RESPONSIBLE DISCLOSURE

Page 7: Disclosing Vulnerabilities for Fun and Profit
Page 8: Disclosing Vulnerabilities for Fun and Profit
Page 9: Disclosing Vulnerabilities for Fun and Profit

Tools Proxy:

Burp Suite

Web Scarab

Fiddler

And many more…!!!

Firefox Addons:

Tamper Data

Web Developer Extensions

Live HTTP Headers

Firebug

Hackbar

XSS Me

And many more…!!!

Optional:

Camtasia Studio(Screen Recorder)

Snipping Tool(Screenshots)

Useful Tools:

IRONWASP

XENOTIX

And many more…!!!

Page 10: Disclosing Vulnerabilities for Fun and Profit

$100 to $20,000

$500 to $5000

500 to $3000

Page 11: Disclosing Vulnerabilities for Fun and Profit

Unknown Price money (Approx. $50 to $10,000)

$500 + T-Shirt

Page 13: Disclosing Vulnerabilities for Fun and Profit

Normal

Resume Resume with

HOF

Page 14: Disclosing Vulnerabilities for Fun and Profit

Find Bugs

Report Them

Get Reward

Party

Broke

Page 15: Disclosing Vulnerabilities for Fun and Profit

Never go for Full Disclosure without company’s permission.

Always see that, you’ve made a Responsible Disclosure before going for

Full Disclosure.

Page 16: Disclosing Vulnerabilities for Fun and Profit

KEEDA Project A NULL Community Initiative

Highlights:

Informs the vendors and Certs about any

vulnerabilities found in the wild.

The credit is given to the bug submitter

itself.

Does not charge the vendor in return.

But at least a thank you letter from the

Vendor.

If vendor does not rectify the bug, the

FULL DISCLOSURE of the bug is done using

Keeda Portal.

Page 17: Disclosing Vulnerabilities for Fun and Profit
Page 18: Disclosing Vulnerabilities for Fun and Profit
Page 19: Disclosing Vulnerabilities for Fun and Profit
Page 20: Disclosing Vulnerabilities for Fun and Profit
Page 21: Disclosing Vulnerabilities for Fun and Profit

Stored XSS in the Official Website of

DELL

Page 22: Disclosing Vulnerabilities for Fun and Profit
Page 23: Disclosing Vulnerabilities for Fun and Profit

DEMO

Page 24: Disclosing Vulnerabilities for Fun and Profit

XSS CSRF SQLi And many

more

Page 25: Disclosing Vulnerabilities for Fun and Profit
Page 26: Disclosing Vulnerabilities for Fun and Profit
Page 27: Disclosing Vulnerabilities for Fun and Profit
Page 28: Disclosing Vulnerabilities for Fun and Profit

Kislay Bhardwaj

Prashanth.K.V

Riyaz Walikar

Amol Naik

Prasanna Kangasabai

Akash Mahajan

Sabari Selvan

Srikanth Rao

Himanshu Kumar Das

Suriya Prakash

Harsimram Walia

Lava Kumar

And the whole of NULL Bangalore Chapter.

Page 29: Disclosing Vulnerabilities for Fun and Profit

Thank You

NULL Bangalore

Nikhil.P.Kulkarni www.facebook.com/nikchillz www.twitter.com/nikchillz