aishwarya cms

21
By- Aishwarya Iyer CISC (3 months) CONTENT MANAGEMENT SYSTEM

Upload: aishwarya-iyer

Post on 10-Jan-2017

127 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Aishwarya cms

By- Aishwarya IyerCISC (3 months)

CONTENT MANAGEMENT SYSTEM

Page 2: Aishwarya cms

//IndexCMSTypes of CMSCMS - on different platformWhy securityVulnerabilitiesCommon Vulnerability ExposureMitigationsReferences

Page 3: Aishwarya cms

CMS?What is it?

Page 4: Aishwarya cms

//CMS-What is it? A content management system is computer

application that supports the creation and modification of digital content using a blah..blah..blah…!!!!!

Simple meaning: A web app hosted on a web server to help us make a website. A good CMS: Flexible

Easy Administration Tools to make a great website

Advantages:Reduces need to code from scratchuniform look and feel etc..

Page 5: Aishwarya cms

Types of CMS

Page 6: Aishwarya cms

//Types of CMSWeb based (WCMS)

Enterprise (ECMS)

Mobile (MCMS)

Component (CCMS)

Page 7: Aishwarya cms

CMS-on different platforms

Page 8: Aishwarya cms

//CMS-on different platforms Java based:HIPPO CMSMagnolia CMS

ASP.NET based: DotNetNukeMojoPortal

PHP based:DrupalJoomlaWordpress

Page 9: Aishwarya cms

Why Security?

Page 10: Aishwarya cms

//Why Security?

Page 11: Aishwarya cms

Vulnerabilities

Page 12: Aishwarya cms

//Vulnerabilities•Use of Frameworks•Nobody to take responsibility• Virtual gold mine for hackers once vulnerability is discovered•Weak passwords•Different plugins by different developers• SQL injection• XSS

Page 13: Aishwarya cms

Known attacks on CMS

Page 14: Aishwarya cms

//Known Attacks on CMS•Panama Paper leak:

A complete failure of CMS SecurityAttack: Vulnerable CMS PluginsThe hack:Company failed to Encrypt mailsIrresponsible use of CMSOut of date version of component

Page 15: Aishwarya cms

//Known Attacks on CMS•Drupal:Up to 12 million websitesAutomate Attack to take control of the siteNecessary to apply the patches within 7 hours Disadvantage: Automatic update roller

Page 16: Aishwarya cms

//Known Vulnerabilities(CVE’s) CVE-2016-1000138

CVE-2016-1000213

CVE-2016-1000215

CVE-2016-1000216

Many more, here:https://www.cvedetails.com/vulnerability-list/year-2016/month-11/November.html

Page 17: Aishwarya cms

Mitigations

Page 18: Aishwarya cms

//Mitigations• Using Super Strong passwords• Regular Updates• Delete stuffs you don’t use• Set proper Permissions• Disable directory listing

Page 19: Aishwarya cms

//Conclusions

Page 21: Aishwarya cms

Thank you