20155235 "Network attack and Defense" experiment Eight Web Foundation

Source: Internet
Author: User
Tags openvas

20155235 "Network attack and Defense" experiment Eight web basic experiment content
    1. Web front-end HTML (0.5 points)
      Can install normally, start and stop Apache. Understand the HTML, understand the form, understand the get and post methods, and write an HTML containing the form.

    2. Web Front end Javascipt (0.5 points)
      Understand the basic JavaScript functionality and understand the DOM. Write JavaScript to verify the user name, password rules.

    3. Web backend: MySQL Foundation: normal installation, start MySQL, build library, create user, change password, build table (0.5 points)

    4. Web backend: Writing PHP Web pages, connecting databases, authenticating users (1 points)

    5. Simplest SQL injection, XSS attack test (1 points)

Function Description: User can login, login user name password saved in the database, login successfully display welcome page.

Application of a variety of search techniques whois
    • Querying information using the WHOIS command
      Results



Nslookup
    • Use dig -h for help



    • DNS Server query results and cached results for other web sites


    • Use Shodan search engine to query, get:
    • IP anti-domain name query, get:
    • ip2location The query, you have to:

      Tracert Route detection
    • Windows Scenario:
    • Linux conditions:


      Wonderful difference, emmn ...
    • Address of Baidu

      Netdiscover found
    • Under Linux executes netdiscover , to private network segment 192.168. Perform host probing

      Nmap Scan

      command in the diagram





      Perfect

Lab Two vulnerability Scan OpenVAS Vulnerability Scan
    • Input openvas-check-setup , check the installation status, display error, find a solution in 20155232 Lee Shuqi's blog, and resolve
    • openvas-startafter entering, open the browser https://127.0.0.1:9392:





Problem
    1. Which organizations are responsible for the management of DNS,IP.
      A: ICANN is responsible for managing the domain Name System, which has three organizations, the Address support Organization (ASO) manages the IP address system, and the domain support Organization (DNSO) is responsible for the management of the domain Name System (DNS) on the Internet. ; The protocol support organization (PSO) is responsible for assigning unique parameters that involve Internet protocols.
    2. What is 3R information.
      A: The official registration Office, Registrar, registered person
    3. Evaluate the accuracy of the scan results.
      Answer: General ...
Experiment Experience

Feel the experiment where strange, but today really do skull pain, tomorrow change it

20155235 "Network attack and Defense" experiment Eight Web Foundation

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.