1 of 96

Security

Marius Grigaitis | NFQ

marius.grigaitis@nfq.lt

2 of 96

Let’s go by example

3 of 96

4 of 96

5 of 96

6 of 96

7 of 96

8 of 96

9 of 96

10 of 96

11 of 96

12 of 96

13 of 96

14 of 96

15 of 96

16 of 96

17 of 96

18 of 96

19 of 96

I think I saw this somewhere

20 of 96

21 of 96

22 of 96

23 of 96

24 of 96

25 of 96

26 of 96

27 of 96

28 of 96

29 of 96

30 of 96

31 of 96

32 of 96

And not only websites...

33 of 96

34 of 96

https://www.youtube.com/watch?v=00A36VABIA4

35 of 96

36 of 96

37 of 96

38 of 96

39 of 96

40 of 96

41 of 96

42 of 96

43 of 96

44 of 96

There must be a better way!

45 of 96

  1. Protect yourself

46 of 96

Protect yourself - 2FA

47 of 96

Protect yourself - default passwords

48 of 96

Duplicate passwords

49 of 96

Browse safer

50 of 96

Encrypt your disk

51 of 96

Social Engineering

Works in IT also

“Hey Daddy, I’m in a big problem. What’s your email password?”

52 of 96

Social Engineering

53 of 96

Lock your screen!

54 of 96

Lock your screen

55 of 96

Update your software

56 of 96

2. Protect your website

57 of 96

HTTPS

58 of 96

Misconfiguration

  • Same as for user
    • Default passwords
    • Database not firewalled?

59 of 96

Misconfiguration

  • Secured parts are available�Under default URL

60 of 96

Misconfiguration

PHPInfo exposed

61 of 96

Misconfiguration

Directory listing

62 of 96

Misconfiguration

63 of 96

Misconfiguration

64 of 96

Misconfiguration

  • /app/config/parameters.yml file?

65 of 96

Not up to date

https://www.versioneye.com/

  • Not up to date composer packages
  • Server not up to date
  • Firewall rules

66 of 96

ImageMagick

67 of 96

ImageTragick

68 of 96

Insecure direct object access

Hard to enumerate ids?

Information disclosure?

69 of 96

Insecure direct object access

70 of 96

GET /events/1/delete

71 of 96

CSRF

72 of 96

Broken Auth

73 of 96

Broken Auth

74 of 96

Broken Auth

RFC 1149.5 specifies 4 as the standard IEEE-vetted random number.

Obligatory

75 of 96

Broken Auth

Password encoding - one way hash functions

76 of 96

Broken Auth

Is it?

MD5 is

broken!

77 of 96

Broken Auth

78 of 96

Broken Auth

79 of 96

Broken Auth

80 of 96

Broken Auth

81 of 96

XSS

82 of 96

83 of 96

XSS

84 of 96

XSS

Twig

85 of 96

SQL Injection

86 of 96

SQL Injection

87 of 96

Eval

No comments...

88 of 96

tl;dr

Users will send something nice

89 of 96

90 of 96

91 of 96

Anywhere

  • In DELFI comment
  • In HTTP URL
  • In Host Header
  • In Cookie value
  • In an image

92 of 96

Secure by Default

93 of 96

Secure by Default

  • Twig: escapes by default. If we don’t want to escape we have to specify explicitly
  • Firewall: deny from everywhere. Allow only from specific ips
  • ORM / QueryBuilder: escapes all parameters. If we don’t need escaping (why?) we specify.

94 of 96

Contribute

95 of 96

Follow the news!

96 of 96

Question?