gnucitizen pdp owasp usa 2007

33
Copyright © 2007 - The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike 2.5 License. To view this license, visit http://creativecommons.org/licenses/by-sa/2.5/ The OWASP Foundation OWASP USA November 2007 http://www.owasp.org / For my next trick... hacking Web2.0 (lite) Petko D. Petkov (pdp) GNUCITIZEN http://www.gnucitizen.org

Upload: guest20ab09

Post on 17-Dec-2014

994 views

Category:

Business


0 download

DESCRIPTION

GNUCITIZEN presentation on hacking with Web2.0 services, presented at OWASP USA 2007

TRANSCRIPT

Page 1: GNUCITIZEN Pdp Owasp Usa 2007

Copyright © 2007 - The OWASP FoundationPermission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike 2.5 License. To view this license, visit http://creativecommons.org/licenses/by-sa/2.5/

The OWASP Foundation

OWASPUSA

November 2007

http://www.owasp.org/

For my next trick...hacking Web2.0 (lite)

Petko D. Petkov (pdp)GNUCITIZENhttp://www.gnucitizen.org

Page 2: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

powered BY

http://www.gnucitizen.org

Page 3: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...before we START

Feel free to ask questions!Do ask questions!Have fun!

Page 4: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

what is WEB2.0?

Page 5: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

Marketing buzzword Invented by O'Reilly Media in 2003Wikis, Blogs, AJAX, Social Networks,

CollaborationAPIs, SOA (Service Oriented Architecture)Data in the CloudApplications on Demand

Page 6: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

why web2.0 HACKING?

Page 7: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

Data Management Information LeaksLive Profiling Information SpammingService AbuseAutonomous AgentsDistributionAttack Infrastructures

Page 8: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

the PAPER

5 fictional stories with technology that is real

Learn by exampleKISS (Keep it Simple Stupid)Problems with no solutions

I was told that I need to come up with some solutions, otherwise I cannot present at OWASP.

Page 9: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

the STORIES

MPack2.0Attack Infrastructures

WormoholicAutonomous Agents

Bookmarks RiderDistribution

RSS Kingpin Information Spamming

Revealing the hidden WebService Abuse

Page 10: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

know your ROOTS

Page 11: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

what's MPACK?

Page 12: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

what would it be in the web2.0 WORLD?hint: Google Mashup Editor

Page 13: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

who is SAMY?

Page 14: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

what's a covert CHANNEL?

Page 15: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...but in the web2.0 WORLD?

Page 16: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

who's the mechanical TURK?

Page 17: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...to MALWARE?hint: Social Bookmarking

Page 18: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

can web2.0 malware BROADCAST?

Page 19: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...MD5(DOMAIN + TIME)

Page 20: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

where are my SCHEDULERS?

Page 21: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

where are my ACTUATORS?

Page 22: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...data in the CLOUD...

(the malicious one)

Page 23: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...applications on DEMAND...

(the malicious ones)

Page 24: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

what's state and what's PERSISTENCE?

Page 25: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

riding social bookmarks is FUN!

Page 26: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

...maybe make some money TOO!

Page 27: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

to splog or not to splog. This is the QUESTION!

Page 28: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

call me the rss KINGPIN!

Page 29: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

service abuse and the hidden WEB

Page 30: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

know your ROOTS

Page 31: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...more

Profiling targets by watching their Web activities

Snoop onto targetsGEO Position Mobile phonesGEO Position individualsMore service abuseMore vulnerabilitiesMore Insecurities

Page 32: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

...

solutions and recommendations?

Page 33: GNUCITIZEN Pdp Owasp Usa 2007

OWASP USA – November 2007

thank YOU

http://www.gnucitizen.org