<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>sniper &#8211; Réseau CERTA</title>
	<atom:link href="https://www.reseaucerta.org/tag/sniper/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.reseaucerta.org</link>
	<description>Des ressources pour enseigner le numérique</description>
	<lastBuildDate>Wed, 14 Jan 2026 22:36:47 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.reseaucerta.org/wp-content/uploads/cours/cropped-favicon-certa-32x32.png</url>
	<title>sniper &#8211; Réseau CERTA</title>
	<link>https://www.reseaucerta.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>OWASP &#8211; Activité 9: Sécurisation des applications Web Vulnérabilités</title>
		<link>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/</link>
					<comments>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Thu, 19 Jun 2025 15:37:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[authentification]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[identification]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[sniper]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=9566</guid>

					<description><![CDATA[Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="9566" class="elementor elementor-9566">
				<div class="elementor-element elementor-element-66d20fe2 e-con-full e-flex e-con e-parent" data-id="66d20fe2" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-109ff94f e-grid e-con-full e-con e-child" data-id="109ff94f" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-780e2be7 elementor-widget elementor-widget-heading" data-id="780e2be7" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web</h2>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-622f41d8 e-con-full e-flex e-con e-child" data-id="622f41d8" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-a3d6839 e-con-full e-flex e-con e-child" data-id="a3d6839" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2dd24581 elementor-widget elementor-widget-heading" data-id="2dd24581" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné </h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-601a94f2 e-con-full e-flex e-con e-child" data-id="601a94f2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-58231297 elementor-widget elementor-widget-text-editor" data-id="58231297" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class=""><table border="0" width="100%" cellpadding="5"><tbody><tr><td class="reglageContenu">BTS SIO</td></tr></tbody></table></div><div class=""> </div>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-74bc5777 e-con-full e-flex e-con e-child" data-id="74bc5777" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6d227640 elementor-widget elementor-widget-heading" data-id="6d227640" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-9db8b29 e-con-full e-flex e-con e-child" data-id="9db8b29" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-759d0c55 elementor-widget elementor-widget-text-editor" data-id="759d0c55" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Bloc 3 &#8211; Cybersécurité des services informatiques &#8211; SLAM</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-34a378fd e-con-full e-flex e-con e-child" data-id="34a378fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4f06872c e-con-full e-flex e-con e-child" data-id="4f06872c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-698a3d28 elementor-widget elementor-widget-heading" data-id="698a3d28" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation </h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7338c022 e-con-full e-flex e-con e-child" data-id="7338c022" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-186b0270 elementor-widget elementor-widget-text-editor" data-id="186b0270" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Portswigger.net du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.</p><p>Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.</p><p>Dans un premier temps, l&rsquo;étudiant doit comprendre le mécanisme des attaques.</p><p>Dans un deuxième temps, l’objectif est de réaliser des défis à travers des manipulations pratiques.</p><p>Cette neuvième activité concerne les problématiques liées à l&rsquo;identification et l&rsquo;authentification sur u:ne application web. Cette vulnérabilité est classée n°7 dans la classement OWASP 2021.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-29c72dbc e-con-full e-flex e-con e-child" data-id="29c72dbc" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4500daf9 e-con-full e-flex e-con e-child" data-id="4500daf9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-10dded6e elementor-widget elementor-widget-heading" data-id="10dded6e" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Pré-requis</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56ef613b e-con-full e-flex e-con e-child" data-id="56ef613b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-464e5835 elementor-widget elementor-widget-text-editor" data-id="464e5835" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Administration d’un système Linux.</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-69d9fc42 e-con-full e-flex e-con e-child" data-id="69d9fc42" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3206cf30 elementor-widget elementor-widget-heading" data-id="3206cf30" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3b29f42 e-con-full e-flex e-con e-child" data-id="3b29f42" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4771026c elementor-widget elementor-widget-text-editor" data-id="4771026c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-b702bc0 e-con-full e-flex e-con e-child" data-id="b702bc0" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2749ecf3 e-con-full e-flex e-con e-child" data-id="2749ecf3" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-37f645d elementor-widget elementor-widget-heading" data-id="37f645d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3e84b145 e-con-full e-flex e-con e-child" data-id="3e84b145" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-621e6e9 elementor-widget elementor-widget-text-editor" data-id="621e6e9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li>Protéger les données à caractère personnel ;<ul><li>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</li></ul></li><li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.<ul><li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique ;</li></ul></li></ul><p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7dc3cf1a e-con-full e-flex e-con e-child" data-id="7dc3cf1a" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-584469bd e-con-full e-flex e-con e-child" data-id="584469bd" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6b80841b elementor-widget elementor-widget-heading" data-id="6b80841b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f6c46da e-con-full e-flex e-con e-child" data-id="f6c46da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-681c489a elementor-widget elementor-widget-text-editor" data-id="681c489a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Une machine Kali Linux disposant d&rsquo;un accès à internet et du logiciel BurpSuite (disponible sous Windows).</p><p>Sites officiels : <a href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d0a0841 e-con-full e-flex e-con e-child" data-id="d0a0841" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-03fe9c4 e-con-full e-flex e-con e-child" data-id="03fe9c4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-0a489bb elementor-widget elementor-widget-heading" data-id="0a489bb" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1b5c082 e-con-full e-flex e-con e-child" data-id="1b5c082" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-d20d7d8 elementor-widget elementor-widget-text-editor" data-id="d20d7d8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/owasp_activite_9_authentification.pdf">owasp_activite_9_authentification</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp_activite_9_authentificationcorrection.pdf">owasp_activite_9_authentificationcorrection</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-79a9eb41 e-con-full e-flex e-con e-child" data-id="79a9eb41" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5b30f068 e-con-full e-flex e-con e-child" data-id="5b30f068" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2583194c elementor-widget elementor-widget-heading" data-id="2583194c" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-43c88408 e-con-full e-flex e-con e-child" data-id="43c88408" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1ed0370d elementor-widget elementor-widget-text-editor" data-id="1ed0370d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>OWASP, vulnérabilités, identification, authentification, BurpSuite, sniper</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5087b62c e-con-full e-flex e-con e-child" data-id="5087b62c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6eab0261 e-con-full e-flex e-con e-child" data-id="6eab0261" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1d15c967 elementor-widget elementor-widget-heading" data-id="1d15c967" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f90d64d e-con-full e-flex e-con e-child" data-id="f90d64d" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3c555a77 elementor-widget elementor-widget-text-editor" data-id="3c555a77" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>19 Juin 2025</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5cb56c4a e-con-full e-flex e-con e-child" data-id="5cb56c4a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3d5e995 elementor-widget elementor-widget-heading" data-id="3d5e995" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s)</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3e329582 e-con-full e-flex e-con e-child" data-id="3e329582" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-23159e44 elementor-widget elementor-widget-text-editor" data-id="23159e44" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Patrice Dignan, avec la relecture, les tests et les suggestions de Hervé Le Guern.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2a9467d e-flex e-con-boxed e-con e-child" data-id="2a9467d" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
					</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 8 : Sécurisation des applications Web</title>
		<link>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Wed, 13 Nov 2024 19:42:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[sniper]]></category>
		<category><![CDATA[SSRF]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2001</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6205" class="elementor elementor-6205">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe <em>OWASP </em>(<em>OpenWeb Application Security Project</em>) afin de se familiariser avec les principales vulnérabilités des applications <em>Web</em>.</p>

<p>Chaque activité couvre une problématique spécifique (<em>SQLi</em>, <em>XSS</em>, <em>CSRF</em>…) en référence au top 10 des vulnérabilités décrites par l&rsquo;<em>OWASP</em>.</p>

<p>Dans un premier temps, l&rsquo;étudiant doit comprendre le mécanisme des attaques.</p>

<p>Dans un deuxième temps, l’objectif est de réaliser des défis à travers des manipulations pratiques.</p>

<p>&nbsp;</p>

<p><strong>Cette huitième activité</strong> concerne les problématiques liées aux falsifications de requêtes côté serveur(SSRF – Server Side Request Forgery). Cette vulnérabilité a fait son entrée en 10ème position dans le dernier classement OWASP.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>Protéger les données à caractère personnel&nbsp;;
	<ul>
		<li>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</li>
	</ul>
	</li>
	<li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.
	<ul>
		<li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;</li>
	</ul>
	</li>
</ul>

<p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_8_ssrf.odt</strong><br />Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp_activite_8_ssrf.odt" target="_blank" rel="noopener">Télécharger</a> (1.36 MB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_8_correction_ssrf.doc</strong><br />Corrigé disponible &#8211;<strong> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp_activite_8_correction_ssrf.doc">owasp_activite_8_correction_ssrf</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, vulnérabilités, SSRF, BurpSuite, sniper								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									13/11/2024								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice Dignan, avec la relecture, les tests et les suggestions de Hervé Le Guern								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
