SlideShare uma empresa Scribd logo
1 de 22
Securitatea aplicatiilor online
Vulnerabilitati
Solutii folosite ,[object Object],[object Object],[object Object]
Codul scris ,[object Object],[object Object],[object Object],[object Object],[object Object]
Network ,[object Object]
SQL Injection ,[object Object],http://www.example.com/view.php?id_cat=4 "SELECT * FROM data WHERE id_category = " +  $_GET[‘id’]  + ";"  http://www.example.com/view.php?id_cat=4 OR 1=1 "SELECT * FROM data WHERE id = 1 OR 1=1;"  OR 1=1
why ? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Protectie ,[object Object],[object Object],[object Object],[object Object]
Demonstratie
XSS ,[object Object],[object Object],[object Object],[object Object],[object Object]
Non-persistent http://www.example.com?search.php?s= <script>alert(document.cookie)</script>
Rezultatul :
persistent
CSRF/XSRF ,[object Object],[object Object],<img src=“http://www.other-example.com?deleteuser.php?u=vasile” />
Email injection
Codul din spate Nu verificam input-ul String-ul trimis la serverul de mail :
Directory traversal HTTP requests
 
MITM attack
[object Object]
Demonstratie
Concluzii ,[object Object],[object Object],[object Object],[object Object],[object Object]

Mais conteúdo relacionado

Semelhante a Prezentarea "Securitatea Aplicatiilor Online" de la ODO

OWASP Top 10 And Insecure Software Root Causes
OWASP Top 10 And Insecure Software Root CausesOWASP Top 10 And Insecure Software Root Causes
OWASP Top 10 And Insecure Software Root CausesMarco Morana
 
PCI Security Requirements - secure coding
PCI Security Requirements - secure codingPCI Security Requirements - secure coding
PCI Security Requirements - secure codingHaitham Raik
 
Protecting Your Web Site From SQL Injection & XSS
Protecting Your Web SiteFrom SQL Injection & XSSProtecting Your Web SiteFrom SQL Injection & XSS
Protecting Your Web Site From SQL Injection & XSSskyhawk133
 
Web Application Security
Web Application SecurityWeb Application Security
Web Application SecurityJason Leveille
 
Secure software development presentation
Secure software development presentationSecure software development presentation
Secure software development presentationMahdi Dolati
 
Php Security By Mugdha And Anish
Php Security By Mugdha And AnishPhp Security By Mugdha And Anish
Php Security By Mugdha And AnishOSSCube
 
Pci compliance writing secure code
Pci compliance   writing secure codePci compliance   writing secure code
Pci compliance writing secure codeMiva
 
Sql injection
Sql injection Sql injection
Sql injection Aaron Hill
 
Writing Secure Code – Threat Defense
Writing Secure Code – Threat DefenseWriting Secure Code – Threat Defense
Writing Secure Code – Threat Defenseamiable_indian
 
Code injection and green sql
Code injection and green sqlCode injection and green sql
Code injection and green sqlKaustav Sengupta
 
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программирования
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программированияSECON'2017, Евстифеев Петр, Антипаттерны безопасного программирования
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программированияSECON
 
Application Security around OWASP Top 10
Application Security around OWASP Top 10Application Security around OWASP Top 10
Application Security around OWASP Top 10Sastry Tumuluri
 
Java EE Web Security By Example: Frank Kim
Java EE Web Security By Example: Frank KimJava EE Web Security By Example: Frank Kim
Java EE Web Security By Example: Frank Kimjaxconf
 
Protecting your data from SQL Injection attacks
Protecting your data from SQL Injection attacksProtecting your data from SQL Injection attacks
Protecting your data from SQL Injection attacksKevin Alcock
 

Semelhante a Prezentarea "Securitatea Aplicatiilor Online" de la ODO (20)

ASP.NET Web Security
ASP.NET Web SecurityASP.NET Web Security
ASP.NET Web Security
 
OWASP Top 10 And Insecure Software Root Causes
OWASP Top 10 And Insecure Software Root CausesOWASP Top 10 And Insecure Software Root Causes
OWASP Top 10 And Insecure Software Root Causes
 
PCI Security Requirements - secure coding
PCI Security Requirements - secure codingPCI Security Requirements - secure coding
PCI Security Requirements - secure coding
 
Protecting Your Web Site From SQL Injection & XSS
Protecting Your Web SiteFrom SQL Injection & XSSProtecting Your Web SiteFrom SQL Injection & XSS
Protecting Your Web Site From SQL Injection & XSS
 
Web Application Security
Web Application SecurityWeb Application Security
Web Application Security
 
PHPUG Presentation
PHPUG PresentationPHPUG Presentation
PHPUG Presentation
 
Secure software development presentation
Secure software development presentationSecure software development presentation
Secure software development presentation
 
Php Security By Mugdha And Anish
Php Security By Mugdha And AnishPhp Security By Mugdha And Anish
Php Security By Mugdha And Anish
 
Pci compliance writing secure code
Pci compliance   writing secure codePci compliance   writing secure code
Pci compliance writing secure code
 
Sql injection
Sql injection Sql injection
Sql injection
 
Owasp & Asp.Net
Owasp & Asp.NetOwasp & Asp.Net
Owasp & Asp.Net
 
Security 101
Security 101Security 101
Security 101
 
Writing Secure Code – Threat Defense
Writing Secure Code – Threat DefenseWriting Secure Code – Threat Defense
Writing Secure Code – Threat Defense
 
Code injection and green sql
Code injection and green sqlCode injection and green sql
Code injection and green sql
 
Greensql2007
Greensql2007Greensql2007
Greensql2007
 
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программирования
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программированияSECON'2017, Евстифеев Петр, Антипаттерны безопасного программирования
SECON'2017, Евстифеев Петр, Антипаттерны безопасного программирования
 
ieee
ieeeieee
ieee
 
Application Security around OWASP Top 10
Application Security around OWASP Top 10Application Security around OWASP Top 10
Application Security around OWASP Top 10
 
Java EE Web Security By Example: Frank Kim
Java EE Web Security By Example: Frank KimJava EE Web Security By Example: Frank Kim
Java EE Web Security By Example: Frank Kim
 
Protecting your data from SQL Injection attacks
Protecting your data from SQL Injection attacksProtecting your data from SQL Injection attacks
Protecting your data from SQL Injection attacks
 

Mais de Gabriel Curcudel

Cum să crești vânzările online
Cum să crești vânzările online Cum să crești vânzările online
Cum să crești vânzările online Gabriel Curcudel
 
Competitive link analysis si link management
Competitive link analysis si link managementCompetitive link analysis si link management
Competitive link analysis si link managementGabriel Curcudel
 
Local search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM DaysLocal search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM DaysGabriel Curcudel
 
Analiza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2paraleAnaliza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2paraleGabriel Curcudel
 
Long tail - Krumel - IMTO Seo & Sem
Long tail -  Krumel - IMTO Seo & SemLong tail -  Krumel - IMTO Seo & Sem
Long tail - Krumel - IMTO Seo & SemGabriel Curcudel
 
SEO si SEM – strategii pentru afaceri oline
SEO si SEM – strategii pentru afaceri olineSEO si SEM – strategii pentru afaceri oline
SEO si SEM – strategii pentru afaceri olineGabriel Curcudel
 
Working for the client's clients
Working for the client's clientsWorking for the client's clients
Working for the client's clientsGabriel Curcudel
 
Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009Gabriel Curcudel
 
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor WebTraficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor WebGabriel Curcudel
 
Google Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi AdwordsGoogle Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi AdwordsGabriel Curcudel
 
Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?Gabriel Curcudel
 
Cum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De CautareCum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De CautareGabriel Curcudel
 
Webdeveloper Ciprian Berescu
Webdeveloper  Ciprian BerescuWebdeveloper  Ciprian Berescu
Webdeveloper Ciprian BerescuGabriel Curcudel
 
Mituri Despre Antreprenoriat
Mituri Despre AntreprenoriatMituri Despre Antreprenoriat
Mituri Despre AntreprenoriatGabriel Curcudel
 
Online Commercial Intention
Online Commercial IntentionOnline Commercial Intention
Online Commercial IntentionGabriel Curcudel
 

Mais de Gabriel Curcudel (20)

Cum să crești vânzările online
Cum să crești vânzările online Cum să crești vânzările online
Cum să crești vânzările online
 
Local search 2013 Romania
Local search 2013 RomaniaLocal search 2013 Romania
Local search 2013 Romania
 
Competitive link analysis si link management
Competitive link analysis si link managementCompetitive link analysis si link management
Competitive link analysis si link management
 
Local search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM DaysLocal search Romania 2012 - Krumel - SEM Days
Local search Romania 2012 - Krumel - SEM Days
 
Link building Tecomm Cluj
Link building  Tecomm ClujLink building  Tecomm Cluj
Link building Tecomm Cluj
 
Analiza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2paraleAnaliza SEO ptr site-uri din 2parale
Analiza SEO ptr site-uri din 2parale
 
Long tail - Krumel - IMTO Seo & Sem
Long tail -  Krumel - IMTO Seo & SemLong tail -  Krumel - IMTO Seo & Sem
Long tail - Krumel - IMTO Seo & Sem
 
Lumea Seo Sem Ppc
Lumea Seo Sem PpcLumea Seo Sem Ppc
Lumea Seo Sem Ppc
 
SEO si SEM – strategii pentru afaceri oline
SEO si SEM – strategii pentru afaceri olineSEO si SEM – strategii pentru afaceri oline
SEO si SEM – strategii pentru afaceri oline
 
Prezentare IMTO - Krumel
Prezentare IMTO - KrumelPrezentare IMTO - Krumel
Prezentare IMTO - Krumel
 
Working for the client's clients
Working for the client's clientsWorking for the client's clients
Working for the client's clients
 
Seo Vs Copywriting
Seo Vs CopywritingSeo Vs Copywriting
Seo Vs Copywriting
 
Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009Google Analytics The Fruits Salad Sibiu 2009
Google Analytics The Fruits Salad Sibiu 2009
 
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor WebTraficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
Traficul Organic Si Relevanta Pentru Vizitatori A Paginilor Web
 
Google Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi AdwordsGoogle Ad Planner Pentru Plasamente anunturi Adwords
Google Ad Planner Pentru Plasamente anunturi Adwords
 
Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?Cum vinde GOOGLE pentru tine?
Cum vinde GOOGLE pentru tine?
 
Cum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De CautareCum Folosesti Motoarele De Cautare
Cum Folosesti Motoarele De Cautare
 
Webdeveloper Ciprian Berescu
Webdeveloper  Ciprian BerescuWebdeveloper  Ciprian Berescu
Webdeveloper Ciprian Berescu
 
Mituri Despre Antreprenoriat
Mituri Despre AntreprenoriatMituri Despre Antreprenoriat
Mituri Despre Antreprenoriat
 
Online Commercial Intention
Online Commercial IntentionOnline Commercial Intention
Online Commercial Intention
 

Último

The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integrationmarketing932765
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterMydbops
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Kaya Weers
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024TopCSSGallery
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationKnoldus Inc.
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Nikki Chapple
 
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...itnewsafrica
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructureitnewsafrica
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Mark Goldstein
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 

Último (20)

The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL Router
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog Presentation
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
 
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 

Prezentarea "Securitatea Aplicatiilor Online" de la ODO