<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ataques-web &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/ataques-web/</link>
	<description>Feed of posts on WordPress.com tagged "ataques-web"</description>
	<pubDate>Sat, 26 Dec 2009 20:48:15 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Detectando ataques em aplicações Web]]></title>
<link>http://snnangola.wordpress.com/2008/02/06/detectando-ataques-em-aplicacoes-web/</link>
<pubDate>Wed, 06 Feb 2008 20:26:55 +0000</pubDate>
<dc:creator>snnangola</dc:creator>
<guid>http://snnangola.wordpress.com/2008/02/06/detectando-ataques-em-aplicacoes-web/</guid>
<description><![CDATA[  Recebi um link da lista Owasp-Brasilian para o documento &#8216;Detecting Attacks on Web Applicati]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p align="center"> <img src="http://conference.auscert.org.au/conf2007/images/sponsor_logos/owasplogo-test.jpg" align="middle" height="168" width="170" /></p>
<p>Recebi um link da lista <a href="https://lists.owasp.org/mailman/listinfo/owasp-brazilian">Owasp-Brasilian</a> para o <a href="http://www.sans.org/reading_room/whitepapers/logging/2074.php">documento</a> &#8216;Detecting Attacks on Web Applications from Log Files&#8217;. Sao abordados os seguintes topicos:</p>
<pre><tt><tt>1 Abstract......................................................3
2 Introduction..................................................4
3 Attacks on Web Applications...................................5
3.1 Web server log files......................................6
3.2 Primer on HTTP............................................8
3.2.1 HTTP Evasion Techniques..............................12
3.3 Regular Expressions (Regex)..............................14
4 Detecting Attacks............................................15
4.1 Rulebased Detection (static rules)......................20
4.1.1 Negative Security Model..............................20
4.1.2 Positive Security Model..............................21
4.2 Anomalybased Detection (dynamic rules)..................21
4.3 Detecting the OWASP Top Ten 2007.........................22
4.3.1 A1 Cross Site Scripting (XSS)......................22
4.3.2 A2 Injection Flaws.................................26
4.3.3 A3 Malicious File Execution........................32
4.3.4 A4 Insecure Direct Object Reference................33
4.3.5 A5 Cross Site Request Forgery (CSRF)...............35
4.3.6 A6 Information Leakage and Improper Error Handling. 37
4.3.7 A7 Broken Authentication and Session Management. . . .38
4.3.8 A8 Insecure Cryptographic Storage..................39
4.3.9 A9 Insecure Communications.........................40
4.3.10 A10 Failure to Restrict URL Access................41
5 Conclusion...................................................42
6 References...................................................42</tt></tt></pre>
</div>]]></content:encoded>
</item>

</channel>
</rss>
