We are unable to create an online viewer for this document. Please download the document instead.
Get Rich or Die Trying
"Making money on the Web, the black hat way"
2
WhiteHat Sentinel
• Unlimited Assessments – customer controlled and expert
managed – the ability to scan websites no matter how big
or how often they change
• Coverage – authenticated scans to identify technical
vulnerabilities and custom testing to uncover business
logical flaws
• Virtually Eliminate False Positives – Operations Team
verifies results and assigns the appropriate severity and
threat rating
• Development and QA – WhiteHat Satellite Appliance
allows us to service intranet accessible systems remotely
• Improvement & Refinement – real-world scans enable fast
and efficient updates
© 2008 WhiteHat Security, Inc.
The other half of the Top Ten
Percentage likelihood that a website has a particular
vulnerability by class
4
QA overlooks them
Tests what software should do, not what it can be made to do
Scanners can’t identify them
Lack intel igence and don’t know if something worked (or not)
WAFs / IDSs can’t defend them
Al the HTTP requests appear completely normal
Business logic flaws = $$$
3-5 years XSS, SQLi, and CSRF probably on the way out
Online Ballot Stuffing for Fame
and Fortune
Web-based online pol s are an
extremely common way to
capture or sway public opinion.
No niche is too big or too narrow.
6
In response to an Austin
beagle winning the
Westminster Dog Show, the
Austin American Statesman
newspaper held on online poll
(Austin's Best in Show) for
Central Texas (grouped by
breed). Thousands submitted
photos and voted on their
favorite underdogs.
Prize: Bragging rights
Winning the contest was all about percentages, not total
votes...
STATESMAN DOG SHOW
http://www.statesman.com/life/content/life/other/dogshow.html
7
3 ways to cheat
1. Overwhelming the positive votes
2. Overwhelming the negative votes towards
competitors
3. At the last minute create a new dog and give it a
positive vote - no chance of negative votes and you'll
win at 100% positive.
Robert “RSnake” Hansen’s girlfriend’s
co-worker asks him to help her
chihuahua “Tiny” win the contest.
RSnake fires up Burp proxy...
How I Lost a Contest Involving Chihuahuas
http://ha.ckers.org/blog/20080709/how-i-lost-a-contest-involving-chihuahuas/
8
Taking the path of least resistance
attempts #1 - submits 2,000 votes
Burp Proxy
http://portswigger.net/proxy/
RSnake boosts Tiny into 1st...
9
“ChooChoo” pwns Tiny with technique #2
During the last minutes of the contest the competition
submitted 450+ negative votes, which stil made Tiny the
winner in total by more than 2:1, however as a percentage
of positive to negative, Tiny lost by a landslide.
FTW!
Artificial Scarcity DoS
To prevent multiple-purchase of
a scarce item (airline seats,
physical goods, usernames,
etc.), an application wil “lock” the
object for a period of time to
prevent process conflicts.
Add New Comment