Upgrade to Pro — share decks privately, control downloads, hide ads and more …

[bpstudy] OWASP ZAP Vulnerable Assesment.

Yuho Kameda
February 26, 2016
1.3k

[bpstudy] OWASP ZAP Vulnerable Assesment.

2016/2/26 #bpstudy OWASP ZAPに学ぶ、 Webアプリケーションに潜む 脆弱性の調査手法を紹介

Yuho Kameda

February 26, 2016
Tweet

Transcript

  1. ηΩϡϦςΟεΩϟφͷಛ௃ྫ ߲໨ ༗ঈεΩϟφ ແঈεΩϟφ ݕ߲ࠪ໨ ଟ͍ গͳ͍ αϙʔτମ੍ ॆ࣮ جຊతʹແ͍

    Ϩϙʔτग़ྗ ॆ࣮ ؆қ ޡݕ஌ ൺֱతগͳ͍ ൺֱతଟ͍ ݴޠ ೔ຊޠରԠ͋Γ ӳޠ͕ଟ͍ ྉۚ ඇৗʹߴ͍ ແঈ ެ։৘ใ جຊతʹແ͍ ͱͯ΋ଟ͍ ιʔείʔυ ඇެ։ ެ։΋͋Γ ಈ࡞؀ڥ πʔϧʹґଘ πʔϧʹґଘ ※πʔϧʹΑͬͯ಺༰͸ҧ͏ͨΊɺࢀߟఔ౓ͱ͓ߟ͍͑ͩ͘͞ɻ
  2. ηΩϡϦςΟεΩϟφͷಛ௃ྫ ߲໨ ༗ঈεΩϟφ ແঈεΩϟφ OWASP ZAP ݕ߲ࠪ໨ ଟ͍ গͳ͍ ଟ͍

    αϙʔτମ੍ ॆ࣮ جຊతʹແ͍ ίϛϡχςΟ͕ॆ࣮ Ϩϙʔτग़ྗ ॆ࣮ ؆қ ॆ࣮(ӳޠ͕ଟ͍) ޡݕ஌ ൺֱతগͳ͍ ൺֱతଟ͍ ൺֱతগͳ͍ ݴޠ ೔ຊޠରԠ͋Γ ӳޠ͕ଟ͍ ೔ຊޠରԠ͋Γ ྉۚ ඇৗʹߴ͍ ແঈ ແঈ ެ։৘ใ جຊతʹແ͍ ͱͯ΋ଟ͍ ଟ͍ ιʔείʔυ ඇެ։ ެ։΋͋Γ ެ։ ಈ࡞؀ڥ πʔϧʹґଘ πʔϧʹґଘ Windows/Linux/Mac ※πʔϧʹΑͬͯ಺༰͸ҧ͏ͨΊɺࢀߟఔ౓ͱ͓ߟ͍͑ͩ͘͞ɻ
  3. ੬ऑੑΛମݧ֮ͯ͑͠Α͏ OWASP Broken Web Application (BWA) ੬ऑͳWebΞϓϦέʔγϣϯͷ٧Ί߹Θͤ Java / ASP

    / PHP / Ruby on Rails… https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project
  4. ؀ڥ४උ OWASP ZAPͷΠϯετʔϧ OWASP ZAP 2.4.3(2015/12/4 released) ਍அπʔϧ OWASP BWAͷΠϯετʔϧ

    OWASP BWA 1.2 (2015/8/3 released) ਍அର৅ͱͳΔΞϓϦέʔγϣϯ ࣮ࡍʹؼ୐͔ͯ͠Βࢼͯ͠Έ͍ͯͩ͘͞ʂ ४උͷৄࡉ͸ɺԼهͰɻ http://zapjp.blogspot.jp/ https://www.owasp.org/index.php/User:Yuho_Kameda
  5. OWASP ZAPͱ͸ʁ OWASP ZAP (Zed Attack Proxy) WebΞϓϦέʔγϣϯΛ؆୯ʹʮ੬ऑੑ਍ அʯ͢Δ͜ͱ͕Ͱ͖Δπʔϧ ϩʔΧϧϓϩΩγπʔϧ

    https://code.google.com/p/zaproxy/ https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
  6. OWASP BWAͱ͸ʁ OWASP Broken Web Application (BWA) ੬ऑͳWebΞϓϦέʔγϣϯͷ٧Ί߹Θͤ Java /

    ASP / PHP / Ruby on Rails… https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project
  7. ݟ͚ͭͨ੬ऑੑΛ֬ೝʂ • OWASP ZAP Developer Group – ϝϯόʔ਺ɿ434ਓ – ։࢝೔ɿ2010/08/17

    – ओͳ಺༰ • ZAP։ൃʹؔ͢Δ͜ͱ • Extensionͷ։ൃ • όάमਖ਼ • OWASP ZAP User Group – ϝϯόʔ਺ɿ431ਓ – ։࢝೔ɿ2012/05/22 – ओͳ಺༰ • ࢖͍ํͷ࣭໰ • ࣮૷ͯ͠΄͍͠ϦΫΤε τ
  8. ੬ऑੑΛݟ͚ͭΔ࢓ࣄ΁ ੬ऑੑ਍அ࢜ʢWeb ΞϓϦέʔγϣϯʣεΩϧϚοϓ ϓϩδΣΫτ 2014 OWASP Japan / JNSAͷISOG-J ʹΑΔڞಉWG

    ੬ऑੑ਍அ࢜ʹඞཁͳೳྗͷϚοϐϯά ϓϩάϥϚ͔ΒωοτϫʔΫ஌ࣝɺྙཧ؍·Ͱ 2014/12/24 ʮ੬ऑੑ਍அ࢜(WebΞϓϦέʔγϣϯ)εΩϧϚοϓʯެ։ https://www.owasp.org/index.php/Japan http://isog-j.org/output/2014/about-pentester-web-skillmap-201412.pdf