Top Banner
By- Aishwarya Iyer CISC (3 months) CONTENT MANAGEMENT SYSTEM
21

Aishwarya cms

Jan 10, 2017

Download

Technology

Aishwarya Iyer
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Aishwarya cms

By- Aishwarya IyerCISC (3 months)

CONTENT MANAGEMENT SYSTEM

Page 2: Aishwarya cms

//IndexCMSTypes of CMSCMS - on different platformWhy securityVulnerabilitiesCommon Vulnerability ExposureMitigationsReferences

Page 3: Aishwarya cms

CMS?What is it?

Page 4: Aishwarya cms

//CMS-What is it? A content management system is computer

application that supports the creation and modification of digital content using a blah..blah..blah…!!!!!

Simple meaning: A web app hosted on a web server to help us make a website. A good CMS: Flexible

Easy Administration Tools to make a great website

Advantages:Reduces need to code from scratchuniform look and feel etc..

Page 5: Aishwarya cms

Types of CMS

Page 6: Aishwarya cms

//Types of CMSWeb based (WCMS)

Enterprise (ECMS)

Mobile (MCMS)

Component (CCMS)

Page 7: Aishwarya cms

CMS-on different platforms

Page 8: Aishwarya cms

//CMS-on different platforms Java based:HIPPO CMSMagnolia CMS

ASP.NET based: DotNetNukeMojoPortal

PHP based:DrupalJoomlaWordpress

Page 9: Aishwarya cms

Why Security?

Page 10: Aishwarya cms

//Why Security?

Page 11: Aishwarya cms

Vulnerabilities

Page 12: Aishwarya cms

//Vulnerabilities•Use of Frameworks•Nobody to take responsibility• Virtual gold mine for hackers once vulnerability is discovered•Weak passwords•Different plugins by different developers• SQL injection• XSS

Page 13: Aishwarya cms

Known attacks on CMS

Page 14: Aishwarya cms

//Known Attacks on CMS•Panama Paper leak:

A complete failure of CMS SecurityAttack: Vulnerable CMS PluginsThe hack:Company failed to Encrypt mailsIrresponsible use of CMSOut of date version of component

Page 15: Aishwarya cms

//Known Attacks on CMS•Drupal:Up to 12 million websitesAutomate Attack to take control of the siteNecessary to apply the patches within 7 hours Disadvantage: Automatic update roller

Page 16: Aishwarya cms

//Known Vulnerabilities(CVE’s) CVE-2016-1000138

CVE-2016-1000213

CVE-2016-1000215

CVE-2016-1000216

Many more, here:https://www.cvedetails.com/vulnerability-list/year-2016/month-11/November.html

Page 17: Aishwarya cms

Mitigations

Page 18: Aishwarya cms

//Mitigations• Using Super Strong passwords• Regular Updates• Delete stuffs you don’t use• Set proper Permissions• Disable directory listing

Page 19: Aishwarya cms

//Conclusions

Page 21: Aishwarya cms

Thank you