首页 理论教育基于Web安全的渗透测试与防护研究

基于Web安全的渗透测试与防护研究

【摘要】:针对Web应用的安全渗透进行研究,包括信息收集、漏洞扫描、漏洞利用、渗透攻击等阶段,针对SQL注入、任意文件上传等漏洞,采用真实案例,分析渗透测试技术,并最终获取系统的访问权限。同时为应对Web渗透攻击,对安全防护技术进行探索,可采用加固应用系统,并建立行之有效的监控系统来防止恶意入侵。刘刚,本科,助理工程师。

张延国 杨亚萍 刘刚

上海计算软件技术开发中心 上海 201112)

摘要:随着Web技术的发展,Web应用在各个领域得到了广泛的应用,为人类生活和工作带来了极大的便利,但其中也暗藏了一些安全隐患,包括不法分子利用Web应用系统存在的漏洞对其进行恶意攻击等。针对Web应用的安全渗透进行研究,包括信息收集、漏洞扫描、漏洞利用、渗透攻击等阶段,针对SQL注入、任意文件上传等漏洞,采用真实案例,分析渗透测试技术,并最终获取系统的访问权限。同时为应对Web渗透攻击,对安全防护技术进行探索,可采用加固应用系统,并建立行之有效的监控系统来防止恶意入侵。

关键词:Web安全,渗透测试,SQL注入,任意文件上传,安全防护

资助项目:国家自然科学基金(61502299)、上海市科委项目(15511107003、16511101202)。

作者简介:张延国,男,1987年生,硕士,助理工程师,主要从事及研究领域:信息安全。E-mail:yanguoyange@163.com。

杨亚萍,硕士,工程师。(www.chuimin.cn)

刘刚,本科,助理工程师。

Research on Security Penetration and Protection Based on Web——Take an Enterprise Portal Penetration Test as an Example

ZHANG Yanguo YANG Yaping LIU Gang

(Shanghai Development Center of Computer Software Technology, Shanghai 201112, China)

Abstract: With the development of Web technology, web application has been widely developed in various fields. E-commerce sites, hospital registration application system, portal website, OA office system have brought great convenience to our life and work. But criminals make malicious attack on Web application system through its vulnerabilities. It has also become a key security risk. This paper makes research on the security for Web application penetration, including information collection, vulnerability scanning, vulnerability exploitation, penetration attack.According to SQL injection, arbitrary file upload vulnerability, real case analysis is used to make penetration test,and gain ultimate access to the system. At the same time, in order to deal with Web penetration attack, the security protection technology is explored. Strengthening the application system and establishing an effective monitoring system is suggested to prevent malicious intrusion.

Keywords: Web Security, Penetration Testing, SQL Injection, Arbitrary File Upload, Security Protection