Web Page Security
#1

[attachment=12383]
Introduction To Web Page Security
How the web really works?
What is web page login?

• Un-validated Input
• Who is a “hacker“ and who is a “cracker“?
• Tools used for securing the web page
• Insecure storage
Securing the Web page
• Choosing a good password
• Securing Your Network
What is web page???
• A web page or web service is a software application that is accessible using a web browser or HTTP(s) user agent
• Web page Security is“The securing of web applications”.
What is web site??
• Key terms
• Web page
• Web browser
• HTTP
• URL
web page encryption
• Cookies
• On a typical Web server…
 Your host has an open 80/8080 port
 Following components are running
 OS
 web server
 main application (e.g., apache)
 plugins
 servlets
 scripts (CGI, Perl, ...)
Common Web Page Security Mistakes
• Trusting Client-Side Data
• Unescaped Special Characters
• HTML Character Filtering
• Lack of re-authenticating
• Hosting of uncontrolled data on a protected domain
How the web really works?
• Un-validated Input
• Attacker can easily change any part of the HTTP request before submitting
– URL
– Cookies
– Form fields
– Hidden fields
– Headers
• Who is a “hacker“ and who is a “cracker“?
The basic difference:
hackers build things,& crackers break them.
Securing the Web page
• Choosing a good password
• Using Tools
Choosing a good password
 • Retina checks are currently not possible, so guard your password ;-)
 – NEVER give your password to anyone
 • Not even your girl(boy-)friend
 – Make your password something you can remember
 – Make your password difficult for others to guess
 – DO NOT change your password because someone told you to(e.g., via e-mail)
 • Crackers might crack the following passwords:
 – Words in any dictionary, your user name, your name, names of people you know, substituting some characters (a 0 (zero) for an o,or a 1 for an l)
 – http://openwalljohn/ (John, passwd cracker)
Password examples
• • The “Bad”
• – admin
• – 9860456564
• – Rahul
• – Konrad4868
• • The “Good”
• – #bdiBuM1a
• – Qa56Fge(/
• – sdFOiKqw”=
Securing Your Network
• Router
• Firewall
• Switch
• Securing Your Host
• operating system
• .NET Framework
Securing Your Application
• Input Validation
• Authentication
• Authorization
• Exception Management
• Auditing and Logging
Cryptography
• Recognization of Secure page
• Check for the "Lock" icon
• Check the web page URL
• Example of secure web page…
Tools used for securing the web page
• eBay Inc
• WebGoat
• VMware
• Nmap (Network Mapper)
• WebScarab
• Mozilla Firefox
Commonly attacked services
• SMTP servers (port 25)
– sendmail: “The address parser performs insufficient bounds checking in certain conditions due to a char to int conversion, making it possible for an attacker to take control of the application
RPC servers (port 111 & others)
• NetBIOS shares (ports 135, 139, 445)
– Blaster worm
– Sasser worm
• FTP servers (ports 20, 21)
– wuftpd vulnerabilities
• SSH servers (port 22)
– OpenSSH, PAM vulnerabilities
• Web servers (ports 80, 443)
– Apache chunked encoding vulnerability
Reply

Important Note..!

If you are not satisfied with above reply ,..Please

ASK HERE

So that we will collect data for you and will made reply to the request....OR try below "QUICK REPLY" box to add a reply to this page
Popular Searches: web page rankingass, web page development, web page, simple web page code of collge, web page data, web page previews safari, hlml coding of college web page,

[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Possibly Related Threads...
Thread Author Replies Views Last Post
  network security seminars report computer science technology 14 20,528 24-11-2018, 01:19 AM
Last Post:
  Bluetooth Security Full Download Seminar Report and Paper Presentation computer science crazy 21 26,226 07-08-2014, 11:32 PM
Last Post: [email protected]
  Data Security in Local Network using Distributed Firewalls computer science crazy 10 14,939 30-03-2014, 04:40 AM
Last Post: Guest
  web spoofing full report computer science technology 9 11,029 26-03-2014, 06:29 AM
Last Post: Guest
  Web Services Architecture computer topic 0 7,580 25-03-2014, 10:20 PM
Last Post: computer topic
  Security in Data Warehousing seminar surveyer 3 9,942 12-08-2013, 10:24 AM
Last Post: computer topic
  E-COMPILER FOR JAVA WITH SECURITY EDITOR smart paper boy 7 11,867 27-07-2013, 01:06 PM
Last Post: computer topic
  Opera (web browser) computer science crazy 3 4,362 08-07-2013, 12:45 PM
Last Post: computer topic
  E-COMPILER FOR JAVA WITH SECURITY EDITOR seminar class 9 13,641 24-06-2013, 11:44 AM
Last Post: Guest
  Security System using Biometrics ( Download Full Seminar Report ) computer science crazy 7 10,346 02-02-2013, 03:56 PM
Last Post: seminar details

Forum Jump: