spo1 w23 b

11
Session ID: Session Classification:

Upload: selectedpresentations

Post on 14-Apr-2017

73 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Spo1 w23 b

Session ID:

Session Classification:

Page 2: Spo1 w23 b

Page 3: Spo1 w23 b

Page 4: Spo1 w23 b

Get the username

Get the password

Remember the User

Get Sales Data

Edit my account

Generate Reports

Page 5: Spo1 w23 b

SQL Injection

Cross Site Scripting

Improper Session Handling

Data Leakage

Sensitive Information Disclosure

Weak Server Side Controls

Client Side Injection

Insufficient Data Storage

Page 6: Spo1 w23 b
Page 7: Spo1 w23 b

Server

SQL Injection + XSS

Authentication Issues

Session Management

All standard Web Application Checks

Network

Cleartext Credentials

Cleartext Data

Backdoor Data

Data Leakage

Etc.

Client

Credentials in memory

Credentials on File system

Data stored on file system

Poor Cert Management

Etc.

Page 8: Spo1 w23 b

Page 9: Spo1 w23 b
Page 10: Spo1 w23 b

Build Production Test Architecture

& Design Requirements Plan

Mobile Security Development

Standards

Application Specific Threat Modeling and

Analysis

Mobile Secure Coding Training

Mobile Application Security Assessment (Static, Dynamic, Server, Network, Client)

Threat Modeling CBT for Developers

Mobile Secure Coding Standards Wiki

Mobile Risk Dictionary

Mobile Application Security Process

Design

Mobile Firewall

Mobile Security Policies

Static Analysis

Page 11: Spo1 w23 b