Application Intrusion and Forensics; CSI:CF

Comments

very good,I love it.719

Posted By: Coach Shoes On: 07/19/11 4:59 AM

Nice post.....
what an amazing and helpful information for everyone.

Posted By: Dissertation methodology On: 09/16/11 6:03 AM

Always distinguished Aantdhar Jdiedk

Posted By: دردشة On: 09/19/11 5:37 PM

thank you good job

Posted By: شات عسل On: 12/21/11 7:52 PM


White snow boots washing: white snow footwear side: Remember, with white toothpaste + brush + water + soft dry! Oh sure, other detergents or washing powder on the stain color components will make it, so the best toothpaste, the kind of white. White boots: care methods such as the upper water cleansing foam to dry in about 80% of the time to pay attention to SHOES shape the next, or will be wrinkled, generally fine. White snow boots hairy: colorless transparent liquid washing + water + gently + gently twist off the water + natural drying, 80% of the dry, can be a small comb hair + hairy hairy shape, and then air can.

Posted By: uggs for cheap On: 12/21/11 8:14 PM

Thank you
You are already wonderful

Posted By: شات الطائف On: 12/21/11 11:13 PM

Even people that don't personal a pair establish the versions and make.Each and every year, new pleasant types are released. Now the brand name title is identified like a preferred, higher-conclude fashion footwear and is even witnessed on runway versions in common fashion exhibits throughout the world.

Posted By: uggs clearance On: 12/22/11 12:42 AM

Hey, nice work. I understand what you’re trying to say in this post and I like your opinion thanks for sharing.

Posted By: dissertation services On: 12/22/11 2:01 AM

thanks for sharing.

Posted By: Egitim On: 12/22/11 9:23 PM

great work, thank you.

Posted By: Exsohbet On: 12/22/11 9:26 PM

I was in low spirits before,but now i read your writting,i feel a little better!

Posted By: Ken Griffey Jr Shoes On: 12/22/11 9:49 PM

Thank you
I was pleased to be here

Posted By: شات On: 12/22/11 10:05 PM

with this navy blue long coat there is a kind of ice slightly monotonous overall warming effect, so that the color degree more rich and full. With several classic snow boots, many colors are used camel, camel is more of a wild snow boots, if you are still hesitant to buy what color snow boots, buy a camel must be true.

Posted By: uggs boots sale On: 12/23/11 1:18 AM

I was pleased to be here

Posted By: replica Goyard On: 12/23/11 9:46 PM

Thank you for the article, I saw after the enlightened, my idea like you, just not good at expression
~

Posted By: Ken Griffey Shoes On: 12/24/11 3:20 AM

Because the issue is a wonderful and unique and deserves thanks and follow through this new location and beautiful

Posted By: العاب صخر On: 12/25/11 6:19 PM

Concepteur ralph lauren dump sa première visite en Chine some sort of apporté beaucoup d'inspiration dans le dernier automne et l'hiver 2011 Big apple Vogue Full week défilé de manner, plein d'éléments de marque http://www.vetementpoloralphlaure2012.net de l'éolienne de Chine orientale. De soie lisse, mélanger de velours rouge, de Chinois, vert émeraude, jade, corail accessoires fabrique des vêtements avec des saveurs furthermore chinoise et occidentale. Dirigeant chinois, are generally broderie dragon, s'habiller, for example utilisé directement sur le défilé de manner s'avère être devenu une tache lumineuse.

Posted By: ralph lauren On: 12/29/11 2:31 AM

thanks. i lile it.

Posted By: yeni yıl duvar kağıtları On: 12/30/11 4:14 AM

gracias bro.

Posted By: yılbaşı duvar kağıtları On: 12/30/11 4:40 AM

Thank you bro..

Posted By: yılbaşı duvar kağıtları On: 12/30/11 4:49 AM

Do you acknowledge that this is correct time to receive the <a href="http://goodfinance-blog.com">loans</a>, which will realize your dreams.

Posted By: DinaCooke30 On: 01/03/12 9:56 AM

It was great reading your article! Keep up the good work..

Posted By: ألعاب ألغاز On: 01/08/12 11:24 AM

Always distinguished Aantdhar Jdiedk

Posted By: استضافة عراقية On: 01/09/12 6:59 PM

This guidance professional characterized by Thirty-four females and Five . Frequently of being very limited wish.

Posted By: escorte On: 01/10/12 3:48 PM

Monopoly on the more suitable for men UGG UGG snow boots are UGG5825 black style. Some people do not like the UGG snow boots, heavy appearance is normal, if that is a girl snow boots patent on unfair; to be accurate to say, the first to wear these boots, shaving wool workers in Australia, are some men. However, in addition to warmth and comfort factors, from the aesthetic standpoint. This hairy legs wrapped boots, and men seem to not match their temperament.

Posted By: cheap uggs On: 01/11/12 9:12 PM

thanks. i lile

Posted By: شات غلاي On: 01/12/12 8:02 AM

Some time to reach the Academic degree you need purchase thesis abstract referring to this good post and thesis writing.

Posted By: thesis On: 01/12/12 6:03 PM

Upon receipt of a wonderful brother in Antdhar Jdiedk gat iraq

Posted By: دردشة العراق On: 01/13/12 1:40 PM

Upon receipt of a wonderful brother in Antdhar Jdiedk gat iraq

Posted By: دردشة العراق On: 01/13/12 1:45 PM

I'm not positive I completely agree with you on this article. However I am normally open to fresh ideas. May well have to think about it. Solid site anyway.                  

Posted By: Flatshare On: 01/16/12 12:52 AM

When you utilize the buying term papers service, you don't spend your cash. Furthermore, you build your career, buying customized term papers.

Posted By: buy a research paper On: 01/16/12 11:23 AM


Upon receipt of a wonderful brother in Antdhar Jdiedk gat iraq

Posted By: دردشة العراق On: 01/18/12 12:06 PM

There are many reasons to further your education. Sadly, many people allow the business of their lives to keep them away from ever doing so. If you have had that itch to get back to school to further your education and want to once again start hitting the books, then you might want to consider going after an online degree.

Posted By: Law Essay On: 01/21/12 2:11 AM

It's very important when your Internet site has great traffic and I utilize bookmarks submission for it. Moreover, it's not hard to find the online social bookmark service.

Posted By: bookmarking submission services On: 01/22/12 8:58 PM

Add Comment

Comments have been closed.

Transcript

no image

Slide Text

Slide Notes


Application Intrusion and Forensics CSICF Adobe MAX 2010 ColdFusion Unconference

no text exists for this slide

no notes exist for this slide

About me


Working in field for about 14 years
Working in field for about 14 years
Using ColdFusion since version 1.5
Adobe Community Professional
Certified Advanced ColdFusion Developer
Enterprise System Architect; Lead Developer; Principal Programmer for Walt Disney Studios / Studio Production Technology
One of the voices of the <CFHour> podcast

no notes exist for this slide

What is this stuff


Forensics:
Forensics:
The use of science and technology to investigate and establish facts.
CSI:
The application of scientific knowledge and methodology.

no notes exist for this slide

Slide 4


It is not...
It is not...
   'How can I stop them?'
It is...
   'How do I know what they did once they get in?’



Anyone with enough time and motivation will get in.
US Department of Defense gets 70,000 intrusion attempts daily.
Were eventually hacked in June, 2007.
Source: http://spectrum.ieee.org/riskfactor/computing/it/dod_admits_to_being_severely_h

no notes exist for this slide

Anatomy of Actual Intrusion


System was breached by authorized user
System was breached by authorized user
User was granted rights by impersonating someone that should have access
Intruder found unsecured pop-up screens
Intruder wrote program to make thousands of calls to the system
Intruder spread attack over multiple weeks to prevent detection
Intruder only tried to attack system for 10 minutes at a time

no notes exist for this slide

Lets look at the code that was breached

no text exists for this slide

The code for this slide is not included in the presentation attachment.

Intrusion Tracking


Your investigation abilities are only as good as your tracking
Your investigation abilities are only as good as your tracking
Most systems don’t track enough data, or don’t track anything
Most basic tracking done is not reliable
Web server / network logs
Just because they are logged in does not mean they have access.
No one ring to rule them all
It takes multiple tools to track intruders

no notes exist for this slide

What to look for the basics


Traffic that doesn’t follow site map
Traffic that doesn’t follow site map
Page views that happen faster than a person could actually do them
Abnormally large traffic days
Unknown or wrong browser / OS combinations
Invalid entry points

no notes exist for this slide

What will stop an attacker


Web application firewalls will not stop legitimate traffic
Web application firewalls will not stop legitimate traffic
SecureIIS – eEye Digital Security
ModSecurity – Breach Security
FuseGuard – Foundeo Inc.
HTTPS will not stop an attacker. It will just encrypt their intrusion attempts point to point
Well written secure code.
Any data coming from the client should be treated as bad until validated.
Programmers that can think like an attacker

no notes exist for this slide

DEMOs


Basic application with login to protect download page
Basic application with login to protect download page
Track http calls in AIR-based application

no notes exist for this slide

Use the right amount of security for what you are protecting Dont go overboard

no text exists for this slide

no notes exist for this slide

But use enough so that it actually protects

no text exists for this slide

no notes exist for this slide

QA

no text exists for this slide

no notes exist for this slide