OWASP Hacking Lab V1.0
OWASP Hacking Lab V1.0
with Hacking-Lab
Ivan Bütler, E1
Compass Security AG
[email protected]
Goal of this Session
Hacking-Lab Goal:
*Reach the Apply Level*
LiveCD PUBLIC
www.hacking-lab.com
OpenVPN
*VULN APP*
OpenVPN
*VULN APP*
Screenshots of the *VULN APPS*
ASProxy
IIS Webserver + ViewState vulnerabilities
Glocken Franz
Second Order Injection Host
SOAP Interfaces (WSDL Security Challenges)
MySpace
Used for XSS worm development
Oracle Suite
Advanced Oracle SQL Injection Attacks (Alexander Kornbrust)
© Compass Security AG www.csnc.ch Slide 8
Supported Web Hacking Cases
XSRF
JSON Hijacking
SAML/SAML2
Hacking-Lab provides a
free HL LiveCD
„Standardized client
environment for the
students in HL“
Virtual Box Appliance or ISO Image (Ubuntu based)
http://media.hacking-lab.com/largefiles/livecd/
© Compass Security AG www.csnc.ch Slide 12
LiveCD Desktop (OpenVPN ready)
STEP 3
The *difference* makes the
<management application>
The *best* way to explain Hacking-Lab
is to show Hacking-Lab
http://www.hacking-lab.com/sh/8BX0psX
http://www.hacking-lab.com/sh/aBpKnVH