Copyright © 2004 - The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.

Slides:



Advertisements
Similar presentations
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Advertisements

Line Efficiency     Percentage Month Today’s Date
Spotting Web Vulnerabilities (from the eyes of an Script Kiddie)
Open Source/Free Software Source code is available Extensible Can be changed, modified Freely distributed Copies Modified versions Alternatives to commercial/proprietary.
Introduction to Linux Chapter 1. Operating Systems Operating System (OS) - most basic and important software on a computer Performs core tasks Organize.
Open-Source Software ISYS 475.
Drupal Workshop Introduction to Drupal Part 1: Web Content Management, Advantages/Disadvantages of Drupal, Drupal terminology, Drupal technology, directories.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Security Testing Case Study 360logica Software Testing Services.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
The OWASP Foundation OWASP Belgium Chapter OWASP Update Sebastien Deleersnyder Foundation Board, Zenitel Belgium
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © - The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Linda Washington, M.S. U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES Centers for Disease Control and Prevention National Center for Health Statistics Marketing.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Writing Security Alerts tbird Last modified 2/25/2016 8:55 PM.
Rocky Mountain User Group Meeting Lawson Security Presented by Craig Needham Technology Services Manager Lawson Software December 5, 2002.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Web Technology Seminar
Windows Server 2008 R2 Oct 2009 Windows Server 2003
XML & E-COMMERCE SPECIAL INTEREST GROUP (XZIG)
Jan 2016 Solar Lunar Data.

Q1 Jan Feb Mar ENTER TEXT HERE Notes

Project timeline # 3 Step # 3 is about x, y and z # 2
Average Monthly Temperature and Rainfall

2017 Jan Sun Mon Tue Wed Thu Fri Sat

Sebastien Deleersnyder CISSP May, 2006
North Carolina Piedmont Region Consortium Timeline
Gantt Chart Enter Year Here Activities Jan Feb Mar Apr May Jun Jul Aug
Q1 Q2 Q3 Q4 PRODUCT ROADMAP TITLE Roadmap Tagline MILESTONE MILESTONE
Free PPT Diagrams : ALLPPT.com


Jan Sun Mon Tue Wed Thu Fri Sat
Electricity Cost and Use – FY 2016 and FY 2017
SC SC SC WS SC S HIS Background document Seminar document
Unemployment in Today’s Economy
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Q1 Q2 Q3 Q4 PRODUCT ROADMAP TITLE Roadmap Tagline MILESTONE MILESTONE
Free PPT Diagrams : ALLPPT.com

Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Text for section 1 1 Text for section 2 2 Text for section 3 3
Project timeline # 3 Step # 3 is about x, y and z # 2
TIMELINE NAME OF PROJECT Today 2016 Jan Feb Mar Apr May Jun

Q1 Q2 Q3 Q4 PRODUCT ROADMAP TITLE Roadmap Tagline MILESTONE MILESTONE
Presentation transcript:

Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License. The OWASP Foundation OWASP Web server attacks in Belgium – statistics from year 2005 Hillar Leoste Apr, 2006

OWASP 2 Agenda  About Zone-H and defacements  Statistics 2

OWASP 3 What is Zone-h.org News, advisories and opinions, provided from recognized IT security news sites, trusted product vendors and pro-active members of zone-h international community Statistics of most recent digital attacks, surveys and detailed analyses, presented in our regular reports Worth-to-read articles, describing new developments in the IT security world Interviews with leading IT Security industry experts, accompanied by an opportunity to discuss different topics in specialized forums and IRC chatrooms Ongoing evaluations of current digital threats and short-time prognosis Case and motivation studies of digital incidents. Daily newsletters Free Security services: daily “early warning” bulletin + InfoSec pager

OWASP 4 What is Zone-h.org Disclaimer: Zone-h neither: condones, promotes, and/or participates in attacks that are recorded within our database. It is however in a unique position that such attacks are freely reported to our organization. Zone-h catalogues several useful pieces of information for each intrusion including the timestamp of the attack, software version of the webserver, the operating system, motivation of the attacker, and reported technical details of the intrusion methodology.

OWASP 5 Defacement Defacement is an attack against webpage, replacing the main (usually) page with attackers page. Reasons: Political (hacktivism) – Mohammed cartoosns, G8, war in Iran, conflict between Israel and Palestine, etc Best defacer Fun Challenge

OWASP 6 Defacement

OWASP 7 Defacement

OWASP 8 Statistics 2005 for.be Total defacements : 2889 Jan401 Feb320 Mar160 Apr297 May354 Jun189 Jul274 Aug268 Sep85 Oct137 Nov205 Dec199

OWASP 9 Statistics 2005 for.be

OWASP 10 Statistics 2005 for.be By OS: Linux % Windows91932 % BSD531 % Mac461 % Solaris201 % Tru64171 % Unknown101 % By webserver: Apache % IIS91331 % Roxen381 % Unkown170.5 % Lotus-Domino10.5 % WebSTAR10.5 % Zeus10.5 %

OWASP 11 Statistics 2005 for.be By attack type: File inclusion1090 Passwords327 Other web app bug303 SQL Injection276 Not available225 FTP server intrusion127 Web server intrusion122 MITM86 Other server intrusion57 Web server ext. module57 Radmin panel attacks52 DNS attacks52 URL poisoning19 Known vuln.19 SSH server intrusion16 Mail server intrusion15 Telnet server intrusion14 Shares8 Firewall attacks8 0day6 RPC server intrusion5 Brute force 3 Misconfig2

OWASP 12 Statistics 2005 for.be By apps: forum222 guestbook/gastenboek/gastje95 foto/photo13 blog12 bb210 nuke3 gallery3

OWASP 13 Statistics 2005 for.be ?