www.biznet.com.tr
Web Uygulama Güvenliğinde Doğru Bilinen Yanlışlar !
Deniz Çevik Güvenlik Testleri Yöneticisi deniz.cevik@biznet.com.tr
Web Uygulama Gvenliinde Doru Bilinen Yanllar ! Deniz evik Gvenlik - - PowerPoint PPT Presentation
www.biznet.com.tr Web Uygulama Gvenliinde Doru Bilinen Yanllar ! Deniz evik Gvenlik Testleri Yneticisi deniz.cevik@biznet.com.tr Gndem Ksaca Biznet Web Uygulama Mimarisine Ksa Bir Bak Uygulama Gvenlii
www.biznet.com.tr
Deniz Çevik Güvenlik Testleri Yöneticisi deniz.cevik@biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
Web Sunucu Kullanıcı
Web Sunucular
Apache Microsoft-IIS nginx lighttpd Apache-Coyote IBM_HTTP_Server Jetty Sun-ONE-Web-Server Lotus-Domino Sun GlassFish JBOSS
Uygulamalar
Uygulama Sunucuları SQL Database
Veri Tabanları İstemci
HTTP/HTTPS
Diğer Bağlantılar
XMLRPC
Web Sunucu Web Servisleri (WSDL)
SOAP XML
Web Sunucu
GÜVENLİK DUVARI
XML Database LDAP
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
istekleri
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
Diğer Unsurlar (Reverse Proxy, LB, Firewall Sistemleri vb) Veri Tabanı Uygulama Uygulama Sunucu/Framework Web Sunucu İşletim Sistemi TCP/IP Alt Yapısı
www.biznet.com.tr
POST /zkau HTTP/1.1 Host: localhost Connection: keep-alive Content-Length: 143 ZK-SID: 5609 User-Agent: Mozilla/5.0 (Windows NT 6.0; WOW64) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.78 Safari/535.11 Content-Type: application/x-www-form- urlencoded;charset=UTF-8 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-GB,en-US;q=0.8,en;q=0.6 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3 dtid=z_i6l&cmd_0=onClick&uuid_0=zk_comp_664 HTTP/1.1 200 OK Content-Length: 22349 Content-Type: text/plain;charset=UTF-8 ZK-SID: 5609 X-Powered-By: Servlet/2.5 JSP/2.1 {"rs":[["rm",["zk_comp_783"]],["rm",["zk_comp_868"]],["rm",[ "zk_comp_886"]],["rm",["zk_comp_794"]],["rm",["zk_comp_78 4"]],["rm",["zk_comp_867"]]} POST /uyg.gwt HTTP/1.1 Host: localhost Connection: keep-alive X-GWT-Module-Base: /uyg/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.168 Safari/535.19 Content-Type: text/x-gwt-rpc; charset=UTF-8 X-GWT-Permutation: 1F4EA12941 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-GB,en-US;q=0.8,en;q=0.6 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3 5|0|7|http://localhost/uyg.gwt/|29F4EA1240F157649C12466F 01F46F60|com.test.client.GreetingService|greetServer|java.la ng.String|myInput1|myInput2|1|2|3|4|2|5|5|6|7| HTTP/1.1 200 OK Content-Length: 22349 Content-Type: text/plain;charset=UTF-8 X-Powered-By: Servlet/2.5 JSP/2.1 [{"s1":"ABC",«i1":81.284083,"change":-0.007986}]
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr
www.biznet.com.tr