首页> 外文会议>International Conference on Information Security and Cyber Forensics >Dictionary attack on Wordpress: Security and forensic analysis
【24h】

Dictionary attack on Wordpress: Security and forensic analysis

机译:关于WordPress的字典攻击:安全和法医分析

获取原文

摘要

The effective forensic investigation of a security attack on a web application relies on the forensic readiness of the web application system, supportive forensic tools, and skills of the forensic investigator. Web application forensic readiness incorporates evidence collection by enabling logging and the evidence protection for those log files through techniques such as permission settings in order to retain the integrity. Furthermore, a forensic investigator should have a good comprehension of web application functionality, web server architecture, and web application security issues. This paper focuses on a dictionary attack experiment against Wordpress (a web application) administered by a persona named Peter Quill (a fictitious character). The dictionary attack was able to successfully guess the seven-character password used for the persona's user account. A set of techniques and tools are critically analysed to determine whether they can be applicable to the experiment scenario. The techniques mostly focus on retrieving the log files from the web server, the application server, the database server, and the web application itself, while the tools deal with collecting, analysing, and presenting the log file data.
机译:对Web应用程序安全攻击的有效法医调查依赖于Web应用系统的法医准备,支持性取证工具和法医调查员的技能。 Web应用程序取消信件通过能够通过诸如权限设置之类的技术实现这些日志文件来纳入证据集合,以便保留完整性。此外,法医调查员应该对Web应用程序功能,Web服务器体系结构和Web应用程序安全问题的良好理解。本文侧重于由名为Peter Quill(虚构角色)管理的WordPress(Web应用程序)的字典攻击实验。字典攻击能够成功猜出用于Persona用户帐户的七个字符密码。严重分析了一组技术和工具,以确定它们是否适用于实验场景。这些技术主要侧重于从Web服务器,应用程序服务器,数据库服务器和Web应用程序本身检索日志文件,而工具处理收集,分析和呈现日志文件数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号