190 likes | 428 Views
Penetration Testing – A Case Study of Khon Kaen University Networks. การทดสอบเจาะระบบ - กรณีศึกษาเครือข่ายของมหาวิทยาลัยขอนแก่น. COE2007-04. Advisor Kitt Tientanopajai , D.Eng Co-Advisor Assoc.Prof . Arnut Chaosakul Assoc.Prof . Pichate Chiewthanakul Member
E N D
Penetration Testing – A Case Study of KhonKaen University Networks การทดสอบเจาะระบบ - กรณีศึกษาเครือข่ายของมหาวิทยาลัยขอนแก่น
COE2007-04 • Advisor • KittTientanopajai, D.Eng • Co-Advisor • Assoc.Prof. ArnutChaosakul • Assoc.Prof. PichateChiewthanakul • Member • Mr. PongphopLaochaikun 473040597-8 • Miss ArttapornPansamdang 473040629-1
Agenda • Progress • Result of Penetration • Introduction to WeVSA • WeVSA Operational Procedure • Problem • Future work • Demo
Progress Comment: In Progress Not started Finished
Result of Penetration 1/4 • 51 servers tested • 7 Critical Vulnerabilities
WeVSA Operational Procedure 1/3 Server’s name Scan Attack
Server’s name Signal for Start Result
Java Script Injection Etc.. Hidden filed Attack Cross-Stie Scripting Etc.. <script>alert(Document.cookie);</script> SQL Injection Etc.. [T’ or 1=1 --]
WeVSA Operational Procedure 2/3 Target Attack
Penetrate by technique Target Result http response
Problem • WeVSA waiting for scanning from scanner solved by use Thread. • WeVSA must clear results from last scanning. First program cannot delete results because objects was connected with file. We solved by clear garbage collection before deleted.
Future work • Implement WeVSA • Documentation • Penetrate network systems
Anyone has any question? Thank you for your listening