lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAE8h2mRowmAyW=-9+AN7himoSukzbQCSv7ineqE3BCc6HK+HPQ@mail.gmail.com>
Date: Fri, 25 May 2012 13:44:54 -0300
From: Urlan <urlancomp@...il.com>
To: Federico De Meo <adegod@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Info about attack trees

Federico,

Check this out: http://cwe.mitre.org/top25/

2012/5/25 Federico De Meo <adegod@...il.com>

> Hello everybody, I'm new to this maling-list and to security in general.
> I'm here to learn and I'm starting with a question :)
>
> I'm looking for some informations about attack trees usage in web
> application analysis.
>
> For my master thesis I decided to study the usage of this formalism in
> order to reppresent attacks to a web applications.
> I need a lot of use cases from which to start learning common attacks
> which can help building a proper tree.
>
> >From where can I start?
>
> I've already read the OWASP top 10 vulnerabilities an I'm familiar with
> XSS, SQLi, ecc. however I've no clue on how to combine them together in
> order to perform the steps needed to attack a system. I'm looking for some
> examples and maybe to some famous attacks from which I can understand which
> steps are performed and how commons vulnerabilities can being combined
> together. Any help is really appreciated.
>
>
> -------------------
> Federico.
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
Cordialmente,

Urlan Salgado de Barros
CompTIA Security+ Certified
MSc. in Applied Informatics
Bachelor on Computer Science

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ