Network Security Consulting Agency Since 1989 - Specialized in Unix, Windows, TCP/IP and Internet
You are here
:
Home
>
Resources
>
Lectures
> Webshells, real threat for information systems ?
Search
:
Services
Skills & Expertise
Consulting
ISO 27001 services
Vulnerabilities monitoring
Audit & Assessment
Penetration tests
Vunerability assessment (TSAR)
Technical assistance
Training courses
E-learning
Conferences
Agenda
Past events
Tutorials
Resources
Thematic index
Tips
Lectures
Courses
Articles
Tools (download)
Vulnerability watch
Company
Hervé Schauer
Job opportunities
Credentials
History
Partnerships
Associations
Press and
communication
HSC Newsletter
Press review
Press releases
Publications
Contacts
How to reach us
Specific inquiries
Directions to our office
Hotels near our office
Webshells, real threat for information systems ?
Access to the content
Beginning of the presentation
PDF version
[657 KB]
Adobe Flash version
Description
This meeting aimed to describe webshells possibilities once deployed on a Web server and means to protect an information system against this threat.
Context & Dates
Talk presented during the GS-Days 2009, on 1 December 2009.
Author
Renaud Dubourguais
Type
[
-
]
Abstract &
Table of content
Flyleaf
Mise en situation
Retours d'expérience HSC
Impacts de ces vulnérabilités
Webshell ?
Webshell ?
Un Webshell en image ...
Déploiement d'un Webshell
Déploiement d'un Webshell
Prise de contrôle du serveur Web
Prise de contrôle du serveur Web (1/3)
Prise de contrôle du serveur Web (2/3)
Prise de contrôle du serveur Web (3/3)
Reconnaissance du réseau interne
Reconnaissance du réseau interne
Rebond au sein du SI
Rebond au sein du SI (1/2)
Rebond au sein du SI (2/2)
Comment s'en prémunir ?
Les modes de sécurité (1/2)
Les modes de sécurité (2/2)
Quelques pistes ...
Conclusion
Conclusion
Questions ?
Related documents
HTTP (HyperText Transfer Protocol)
Évolution des attaques de type Cross Site Request Forgery
[1 June 2007 -
]
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Tunnels detection at network border
[2 June 2006 -
]
Détection de tunnels aux limites du périmètre
[2 June 2006 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
Subweb tool
[HTTP reverse proxy -
]
Prospects and drawbacks of the new HTTP versions
[24 October 1996 -
]
HTTP/1.1
[6 June 1996 -
]
Using HTTP/1.1 for building a security proxy
[19 March 1996 -
]
Internet
Internet/intranet Security
Deperimetrization or not ?
[22 November 2007 -
]
Evolution of Cross-Site Request Forgery Attacks
[1 June 2007 -
]
DOS on Internet infrastructure
[4 November 2003 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
Internet Familial by SmartValley
[29 June 2000 -
]
SIAM et l'Internet
[25 April 1996 -
]
KBT
[5 February 1996 -
]
La stratégie de France Télécom
[10 January 1996 -
]
Telekom On Line
[4 January 1996 -
]
Droit et l'Internet
[4 December 1995 -
]
Les décisions françaises concernant les projets sur les Autoroutes de l'Information
[23 October 1995 -
]
How to build a secure Internet access architecture?
[October 1995 -
]
Wanadoo
[6 July 1995 -
]
L'Homme Symbiotique
[18 April 1995 -
]
Reverse proxy
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Implementing filtering on a reverse HTTP proxy using mod_eaccess
[3 September 2001 -
]
Filtering URLs in a reverse proxy
[5 May 2001 -
]
Why a reverse proxy
[13 February 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Web
Web Servers and applications Security
Security issue seen in enterprises web applications
[27 November 2008 -
]
Application security
[23 October 2008 -
]
Feedback from PHP applications assessment
[21 November 2007 -
]
Evolution of Cross-Site Request Forgery Attacks
[1 June 2007 -
]
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Web 2.0 : more ergonomic... and less secure ?
[22 May 2007 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Database and ERP security
[15 June 2005 -
]
SSL VPN connection multiplexing techniques
[7 April 2005 -
]
PHP and security
[27 November 2003 -
]
Web Services and Security
[10 September 2003 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
The cross-site scripting
[27 February 2003 -
]
DBMS and security
[1 April 2002 -
]
Apache and web servers security
[1 February 2002 -
]
Implementing filtering on a reverse HTTP proxy using mod_eaccess
[3 September 2001 -
]
Subweb tool
[HTTP reverse proxy -
]
Babelweb tool
[Automatic information retrieving from of a web server -
]
Universal CGI wrapper
[5 August 2001 -
]
Why HTTPS is not web security
[7 May 2001 -
]
Filtering URLs in a reverse proxy
[5 May 2001 -
]
Hacking web servers
[14 March 2001 -
]
Why a reverse proxy
[13 February 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 September 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 April 2000 -
]
Secure Internet services (email, DNS, web) under Linux
[1 February 2000 -
]
Netscape
[16 January 1996 -
]
Penetration tests
Vunerability assessment (TSAR)
Penetration tests
Ethical and Practical Hacking
Web Attacks with Smartphone
[4 June 2009 -
]
Security issue seen in enterprises web applications
[27 November 2008 -
]
Feedback on security audits
[1 April 2008 -
]
WSPP tool
[WSPP -
]
Modern techniques of IP attacks
[18 March 2003 -
]
Audits, Assessments and Penetration Tests
[22 January 2003 -
]
Audits, Assessments and Penetration Tests
[26 June 2002 -
]
Nmap's hidden option
[27 December 2000 -
]
Introduction to intrusion tests
[17 March 1998 -
]
Tests and evaluation of Internet security solutions
[30 May 1997 -
]
Intrusion tests
[December 1996 -
]
Apache
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Apache and module management
[17 October 2003 - ]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
Apache and web servers security
[1 February 2002 -
]
Apache: Virtual hosts and SSL (mod_ssl)
[21 December 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Copyright
© 2009, Hervé Schauer Consultants, all rights reserved.
Last modified on 8 December 2009 at 20:41:44 CET - webmaster@hsc.fr
Information on this server
- © 1989-2010 Hervé Schauer Consultants