Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Reversing Engineering Web Applications for Security - Behavior Analysis and WAF Detection

OWASP Foundation via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore reverse engineering techniques for web applications, focusing on behavior analysis and WAF detection in this 47-minute conference talk from AppSecUSA 2014. Delve into the challenges of screening HTTP traffic and learn about a new approach to mitigate complex attacks on popular CMS platforms. Discover how to integrate traffic analysis with log correlation for improved protection, generating millions of alerts daily with low false positive rates. Follow the speaker's journey through reverse engineering CMS applications, setting up honeypots, identifying attacker behavior, and creating effective countermeasures. Gain insights into live analysis techniques that merge various security strategies to block specific attacks efficiently. Learn from an experienced security professional about the latest developments in web application security, including practical examples and real-world scenarios.

Syllabus

Intro
About Sucuri Security
A Note on the Examples
Motivations
Agenda
Reverse Engineering
Whitelisting
Our Scope: Waf Detection
Detection steps Analyze Application Structure
The HTTP Protocol
Traffic Analysis
Crawling the Application
GET Request
Oh wait! Get a job from the headers...
Full Request
What's wrong here?
What about here?
Summary of Flow Parsing
File Structure
WordPress Tarball
The Basic WP Structure
xmlrpc.php
XMLRPC Login Attempt
Brute forcing New Brute Force Attacks Exploiting XMLRPC in
Pingback
wp-admin/ "Access"
Restriction Samples: .htaccess
Mitigating Attack Surface
Realtime Monitoring w/ OSSEC
Threshold Ideas
Special File Permissions
Counter Intelligence
Behavior: How you look at problems
GEO IP Block: Top Attack Countries
Top Methods
HTTP Version 1.0
In summary...

Taught by

OWASP Foundation

Reviews

Start your review of Reversing Engineering Web Applications for Security - Behavior Analysis and WAF Detection

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.