<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mutillidae 2.6.60 &#8211; Réseau CERTA</title>
	<atom:link href="https://www.reseaucerta.org/tag/mutillidae-2660/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.reseaucerta.org</link>
	<description>Des ressources pour enseigner le numérique</description>
	<lastBuildDate>Wed, 10 Dec 2025 06:41:44 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.reseaucerta.org/wp-content/uploads/cours/cropped-favicon-certa-32x32.png</url>
	<title>Mutillidae 2.6.60 &#8211; Réseau CERTA</title>
	<link>https://www.reseaucerta.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>OWASP &#8211; Activité 5 : Sécurisation des applications web</title>
		<link>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Mon, 10 Jan 2022 12:51:33 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[injection d’entité externe XML.]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2012</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d’exploiter la plateforme d’apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6214" class="elementor elementor-6214">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d’une plateforme d’apprentissage des vulnérabilités des applications Web - Activité 5 : Attaques de type XXE (XML External Entities)</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d’exploiter la plateforme d’apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.<br />
Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.<br />
Dans un premier temps, l’étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.<br />
Cette cinquième activité traite des vulnérabilités de type XXE (XML External Entities). Cette faille arrive en 5ᵉ position dans le classement OWASP 2021.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1. Langage XML.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>&nbsp;&nbsp;&nbsp; • Protéger les données à caractère personnel&nbsp;;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.<br />
&nbsp;&nbsp;&nbsp; • Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.<br />
&nbsp;&nbsp;&nbsp; • Assurer la cybersécurité d’une solution applicative et de son développement.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec <em>Linux</em> comme système d’exploitation.</p><p>Sites officiels :<br /><u><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a></u> et <u><a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></u></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.odt</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite5-v1.0.odt" target="_blank">Télécharger</a> (212.04 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite5-v1.0.pdf" target="_blank">Télécharger</a> (239.38 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite5-v1.0.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR, injection d’entité externe XML.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									10/01/2022								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Valéry Tschaen et Amal Hecker.								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 4 Brèche sur des informations confidentielles</title>
		<link>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Sat, 07 Nov 2020 12:01:03 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2022</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2022" class="elementor elementor-2022">
				<div class="elementor-element elementor-element-3c7f100d e-con-full e-flex e-con e-parent" data-id="3c7f100d" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-1858d499 e-grid e-con-full e-con e-child" data-id="1858d499" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-7ce9681 elementor-widget elementor-widget-heading" data-id="7ce9681" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web
<br><br>Activité 4 : Brèche sur des informations confidentielles
</h2>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1ccf21b5 e-con-full e-flex e-con e-child" data-id="1ccf21b5" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c2c235 e-con-full e-flex e-con e-child" data-id="5c2c235" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-39dd0cd elementor-widget elementor-widget-heading" data-id="39dd0cd" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2ed17df1 e-con-full e-flex e-con e-child" data-id="2ed17df1" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4a3084f9 elementor-widget elementor-widget-text-editor" data-id="4a3084f9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>BTS SIO</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4853e7d9 e-con-full e-flex e-con e-child" data-id="4853e7d9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-538d082f elementor-widget elementor-widget-heading" data-id="538d082f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-226be346 e-con-full e-flex e-con e-child" data-id="226be346" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7d7bea25 elementor-widget elementor-widget-text-editor" data-id="7d7bea25" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Bloc 3 &#8211; Cybersécurité des services informatiques &#8211; SLAM</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7dbdbc9b e-con-full e-flex e-con e-child" data-id="7dbdbc9b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-37862af9 e-con-full e-flex e-con e-child" data-id="37862af9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2df9c65d elementor-widget elementor-widget-heading" data-id="2df9c65d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62b5fb6a e-con-full e-flex e-con e-child" data-id="62b5fb6a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-15efff9 elementor-widget elementor-widget-text-editor" data-id="15efff9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe <em>OWASP </em>(<em>OpenWeb Application Security Project</em>) afin de se familiariser avec les principales vulnérabilités des applications <em>W</em><em>eb</em>.</p><p>Chaque activité couvre une problématique spécifique (<em>SQLi</em>, <em>XSS</em>, <em>CSRF</em>…) en référence au top 10 des vulnérabilités décrites par l&rsquo;<em>OWASP</em>.</p><p>Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.</p><p>Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p><p><strong>Cette </strong><strong>quatrième</strong><strong> activité</strong> traite des vulnérabilités associées aux brèches sur des informations confidentielles. Cette faille arrive en 3ième position dans le classement <em>OWASP</em> 2017.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-35c8dbf0 e-con-full e-flex e-con e-child" data-id="35c8dbf0" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4f9531d1 e-con-full e-flex e-con e-child" data-id="4f9531d1" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-489e8135 elementor-widget elementor-widget-heading" data-id="489e8135" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Pré-requis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				<div class="elementor-element elementor-element-3ac2d3a2 elementor-widget elementor-widget-text-editor" data-id="3ac2d3a2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1.</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-138f560a e-con-full e-flex e-con e-child" data-id="138f560a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-129853f3 elementor-widget elementor-widget-heading" data-id="129853f3" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				<div class="elementor-element elementor-element-82935e6 elementor-widget elementor-widget-text-editor" data-id="82935e6" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li><p>Chiffrement, authentification et preuve ; principes et techniques ;</p></li><li><p>Sécurité des applications web : risques, menaces et protocoles.</p></li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3869c689 e-con-full e-flex e-con e-child" data-id="3869c689" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-7f73f76b e-con-full e-flex e-con e-child" data-id="7f73f76b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-75a263be elementor-widget elementor-widget-heading" data-id="75a263be" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f7228ab e-con-full e-flex e-con e-child" data-id="f7228ab" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2a94c38c elementor-widget elementor-widget-text-editor" data-id="2a94c38c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li><p>Protéger les données à caractère personnel ;</p><ul><li><p>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</p></li></ul></li><li><p>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.</p><ul><li><p>Caractériser les risques liés à l’utilisation malveillante d’un service informatique ;</p></li><li><p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p></li></ul></li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d5a5945 e-con-full e-flex e-con e-child" data-id="d5a5945" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-49e19d6e e-con-full e-flex e-con e-child" data-id="49e19d6e" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5607877d elementor-widget elementor-widget-heading" data-id="5607877d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2d265094 e-con-full e-flex e-con e-child" data-id="2d265094" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-263b3978 elementor-widget elementor-widget-text-editor" data-id="263b3978" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec <em>Linux</em> comme système d’exploitation.</p><p>Sites officiels :<br /><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-49c0a639 e-con-full e-flex e-con e-child" data-id="49c0a639" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-446a68ca e-con-full e-flex e-con e-child" data-id="446a68ca" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5037c3e8 elementor-widget elementor-widget-heading" data-id="5037c3e8" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d47a6bb e-con-full e-flex e-con e-child" data-id="d47a6bb" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-590810e4 elementor-widget elementor-widget-text-editor" data-id="590810e4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/Laboratoires/owasp-activite4-v1.0.pdf">owasp-activite4-v1.0</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/Laboratoires/owasp-activite4-v1.0.odt">owasp-activite4-v1.0</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Corrigé : <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp-activite4Correction-v1.0.zip">owasp-activite4Correction-v1.0</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-10a92eea e-con-full e-flex e-con e-child" data-id="10a92eea" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-60207579 e-con-full e-flex e-con e-child" data-id="60207579" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7d2df509 elementor-widget elementor-widget-heading" data-id="7d2df509" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-38491628 e-con-full e-flex e-con e-child" data-id="38491628" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-c0a5be4 elementor-widget elementor-widget-text-editor" data-id="c0a5be4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class="">OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR.</div>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7af2e1bc e-con-full e-flex e-con e-child" data-id="7af2e1bc" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-7096989b e-con-full e-flex e-con e-child" data-id="7096989b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-41ed9a6b elementor-widget elementor-widget-heading" data-id="41ed9a6b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5c6fdda5 e-con-full e-flex e-con e-child" data-id="5c6fdda5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1ea52ac6 elementor-widget elementor-widget-text-editor" data-id="1ea52ac6" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class="">07 Novembre 2020</div>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3cd01e04 e-con-full e-flex e-con e-child" data-id="3cd01e04" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-683a1c73 elementor-widget elementor-widget-heading" data-id="683a1c73" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-59c3618c e-con-full e-flex e-con e-child" data-id="59c3618c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2b4b8542 elementor-widget elementor-widget-text-editor" data-id="2b4b8542" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Patrice DIGNAN avec la relecture de Valéry TSCHAEN</p>								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 3 : Vulnérabilités de type XSS</title>
		<link>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Sat, 07 Nov 2020 11:56:11 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[cyber-sécurité.]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2023</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2023" class="elementor elementor-2023">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web - Activité 3: Vulnérabilités de type XSS (Cross Site Scripting)</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.<br />
Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.<br />
Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p>

<p>Cette troisième activité traite des vulnérabilités de type XSS (Cross Site Scripting). Cette faille arrive en 7ième position dans le classement OWASP 2017.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>
	<p>Chiffrement, authentification et preuve&nbsp;; principes et techniques&nbsp;;</p>
	</li>
	<li>
	<p>Sécurité des applications web&nbsp;: risques, menaces et protocoles.</p>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>
	<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Protéger les données à caractère personnel&nbsp;;</span></span></p>

	<ul>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</span></span></p>
		</li>
	</ul>
	</li>
	<li>
	<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.</span></span></p>

	<ul>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;</span></span></p>
		</li>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</span></span></p>
		</li>
	</ul>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span style="font-family: Arial,Helvetica,sans-serif;"><span style="font-size: 10pt;">Deux machines éventuellement virtualisées sont nécessaires avec Linux comme système d’exploitation.</span></span></p><p><span style="font-family: Arial,Helvetica,sans-serif;"><span style="font-size: 10pt;">Sites officiels :<br /><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a> </span></span></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3-v1.0.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite3-v1.0.pdf" target="_blank">Télécharger</a> (764.12 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3-v1.0.odt</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite3-v1.0.odt" target="_blank">Télécharger</a> (942.73 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3Correction-v1.0.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite3Correction-v1.0.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR, cyber-sécurité.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									07/11/2020								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Hervé Le GUERN, Yann BARROT, David ROUMANET, Roger SANCHEZ et Valéry TSCHAEN								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
