| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Pogoste ranljivosti spletnih aplikacij in vpliv aplikacijskega požarnega zidu na njihovo varnost : diplomsko delo
Authors:ID Sovič, Vid (Author)
ID Korže, Danilo (Mentor) More about this mentor... New window
Files:.pdf VS_Sovic_Vid_2022.pdf (2,46 MB)
MD5: 5BB8CBD43B5CCFC9A4336F072BF3E7BC
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:Spletne aplikacije so v današnjem času postale ključni del naših dejavnosti v vsakdanjem življenju, kot so na primer zabava, krajšanje časa, raziskovanje in poslovanje. Z vsemi omenjenimi dejavnostmi obstaja možnost, da pride do izkoriščanja teh spletnih storitev z znanimi tipi napadov. Glavni namen diplomskega dela je bil, spoznati deset najpogostejših tipov ranljivosti, predstavljenih v seznamu OWASP iz leta 2021. V sklopu zaključnega dela smo izvedli eksperiment, kjer smo ranljive aplikacije najprej predstavili in demonstrirali prisotno ranljivost, ter v nadaljevanju preizkusili vpliv aplikacijskega požarnega zidu imenovanega ModSecurity. Ugotovili smo, da aplikacijski požarni zid bolje ščiti pred pomanljkljivostmi, ki v zahtevah pošiljajo znano škodljivo in zlonamerno kodo, kot na primer vrivanje stavkov SQL ali ukazne kode. Ranljivosti, ki so povezane z zasnovo aplikacije in površnostjo pri postavitvi, pa v tem primeru niso bile zaščitene.
Keywords:spletne ranljivosti, aplikacijski požarni zid, OWASP, spletni strežnik, vrivanje zlonamernih stavkov, neustrezna kontrola dostopa, ModSecurity, spletna aplikacija
Place of publishing:Maribor
Place of performance:Maribor
Publisher:[V. Sovič]
Year of publishing:2022
Number of pages:1 spletni vir (1 datoteka PDF (XII, 59 f.))
PID:20.500.12556/DKUM-83119 New window
UDC:004.777.056.52(043.2)
COBISS.SI-ID:145541379 New window
Publication date in DKUM:07.11.2022
Views:802
Downloads:114
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.
Licensing start date:20.09.2022

Secondary language

Language:English
Title:Common vulnerabilities in web application and the impact of an application firewall on their security
Abstract:Today, web applications have become a key part of our everyday activities, such as entertainment, shortening the time, research and business. With all these activities, there is a potential for exploiting these web services with known types of attacks. The main purpose of our thesis was to learn about the ten most common types of vulnerabilities presented in the 2021 OWASP list. As part of the thesis, we conducted an experiment where we first presented the vulnerable applications and demonstrated the vulnerabilities present, and further tested the impact of an application firewall called ModSecurity. We found that the application firewall better protects against vulnerabilities that send known malicious and harmful code in requests, such as injecting SQL statements or command code. However, vulnerabilities related to application design and sloppy deployment were not protected in this case.
Keywords:web vulnerabilities, web application firewall, OWASP, web server, injections, broken access control, ModSecurity, web application


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica