Webshells - A Framework for Pentesting.pdf

(5259 KB) Pobierz
WebShells: survey and development
of a framework for penetration testing
19/05/2011
The Boring part ;)
Elena Kropochkina
elena[.]kropochkina[at]gmail[.]com
Elena Kropochkina begins her professional career in Devoteam Audit
Security team. She was graduated by Ecole Polytechnique and Telecom
ParisTech (France) with a M.S. in Computer Science, by Novosibirsk State
University (Russia) with B.S. in Mathematics. She is specialized in IT
Security.
Joffrey Czarny
joffrey[.]czarny[at]devoteam[.]com
Joffrey Czarny, working for Devoteam Security. Since 2001, Joffrey is a
pentester, he has released advisories on VoIP Cisco products and spoken at
various security-focused conferences (Wireless Conference at Infosec Paris
and Wireless Workshop at Hack.lu 2005, VoIP at Hack.lu 2007/2008 and
ITunderground 2008/2009). On his site, www.insomnihack.net, he
maintains the Elsenot project (“http://insomnihack.net/elsenot/”) and
posts video tutorials and tools on several security aspects.
© DEVOTEAM 2010 - page
2
Disclaimer
The presented study is in order to carried out Ethical Hacking
Some tools presented in this slide maybe Unlawful in some
country
Locale legislation must be apply
© DEVOTEAM 2010 - page
3
Summary
Problematic & Objective
State of Art
• Environment study
• WebShell survey
• Obfuscation and protection tools
Conception
Proof-of-concept
• Pieces of code
• Demonstration
Conclusion & perspectives
© DEVOTEAM 2010 - page
4
Summary
Problematic & Objective
State of Art
• Environment study
• WebShell survey
• Obfuscation and protection tools
Conception
Proof-of-concept
• Pieces of code
• Demonstration
Conclusion & perspectives
© DEVOTEAM 2010 - page
5
Zgłoś jeśli naruszono regulamin