<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vulnérabilités &#8211; Réseau CERTA</title>
	<atom:link href="https://www.reseaucerta.org/tag/vulnrabilits/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.reseaucerta.org</link>
	<description>Des ressources pour enseigner le numérique</description>
	<lastBuildDate>Wed, 14 Jan 2026 22:36:47 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.reseaucerta.org/wp-content/uploads/cours/cropped-favicon-certa-32x32.png</url>
	<title>vulnérabilités &#8211; Réseau CERTA</title>
	<link>https://www.reseaucerta.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>SÉCURISATION DES PROTOCOLES RÉSEAUX &#8211; Activité 1 : Évaluer ma sécurité des protocoles POP et SSH</title>
		<link>https://www.reseaucerta.org/securisation-des-protocoles-reseaux-activite-1/</link>
					<comments>https://www.reseaucerta.org/securisation-des-protocoles-reseaux-activite-1/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Thu, 04 Dec 2025 09:15:07 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SISR]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[containers LXC]]></category>
		<category><![CDATA[POP]]></category>
		<category><![CDATA[PROXMOX]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=9686</guid>

					<description><![CDATA[Sécurisation des protocoles réseaux - Évaluation de la sécurité des
protocoles POP et SSH]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="9686" class="elementor elementor-9686">
				<div class="elementor-element elementor-element-5cf14f2b e-con-full e-flex e-con e-parent" data-id="5cf14f2b" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-cf3a4f3 e-grid e-con-full e-con e-child" data-id="cf3a4f3" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-4a7801a0 elementor-widget elementor-widget-heading" data-id="4a7801a0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Sécurisation des protocoles réseaux - Évaluation de la sécurité des
protocoles POP et SSH</h2>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-42937002 e-con-full e-flex e-con e-child" data-id="42937002" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-31bc6ca7 e-con-full e-flex e-con e-child" data-id="31bc6ca7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5f71829 elementor-widget elementor-widget-heading" data-id="5f71829" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5aacd067 e-con-full e-flex e-con e-child" data-id="5aacd067" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-644f8dd8 elementor-widget elementor-widget-text-editor" data-id="644f8dd8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>BTS SIO</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6b17eee3 e-con-full e-flex e-con e-child" data-id="6b17eee3" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-769e5556 elementor-widget elementor-widget-heading" data-id="769e5556" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-630eeb6b e-con-full e-flex e-con e-child" data-id="630eeb6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5994a743 elementor-widget elementor-widget-text-editor" data-id="5994a743" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Bloc 3 SISR –  Cybersécurité des services informatiques</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-25e06113 e-con-full e-flex e-con e-child" data-id="25e06113" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-26bfe87d e-con-full e-flex e-con e-child" data-id="26bfe87d" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3670d612 elementor-widget elementor-widget-heading" data-id="3670d612" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5598066f e-con-full e-flex e-con e-child" data-id="5598066f" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6b40372d elementor-widget elementor-widget-text-editor" data-id="6b40372d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce labo a pour objectifs de maîtriser les techniques de base de reconnaissance réseau, tout en comprenant les vulnérabilités liées aux services mal sécurisés. Les participants apprendront à appréhender les risques associés aux mots de passe faibles et mettront en pratique des outils de sécurité offensive. Enfin, il soulignera l’importance des bonnes pratiques de sécurité pour renforcer la protection des systèmes informatiques.</p><p>Cette <strong>première activité</strong> aborde les enjeux associés aux protocoles POP (pour la messagerie) et SSH (pour l’accès distant sécurisé).</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-28c6f79d e-con-full e-flex e-con e-child" data-id="28c6f79d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3d61f5a e-con-full e-flex e-con e-child" data-id="3d61f5a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1a290432 elementor-widget elementor-widget-heading" data-id="1a290432" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Pré-requis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-64812c1a e-con-full e-flex e-con e-child" data-id="64812c1a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3e5c27a2 elementor-widget elementor-widget-text-editor" data-id="3e5c27a2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Commandes de base d’administration d’un système <em>Linux.</em></p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e77b9ff e-con-full e-flex e-con e-child" data-id="4e77b9ff" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2aec83f3 elementor-widget elementor-widget-heading" data-id="2aec83f3" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7070d261 e-con-full e-flex e-con e-child" data-id="7070d261" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2b196ee8 elementor-widget elementor-widget-text-editor" data-id="2b196ee8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Principes de la sécurité : disponibilité, intégrité, confidentialité, preuve.</p><p>Sécurité des communications numériques : rôle des protocoles, segmentation, administration, restriction.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27cac834 e-con-full e-flex e-con e-child" data-id="27cac834" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-1409784a e-con-full e-flex e-con e-child" data-id="1409784a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-37017d3e elementor-widget elementor-widget-heading" data-id="37017d3e" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cd7bf3e e-con-full e-flex e-con e-child" data-id="1cd7bf3e" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4b9d4b4f elementor-widget elementor-widget-text-editor" data-id="4b9d4b4f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li>Sécuriser les équipements et les usages des utilisateurs ;<ul><li>Identifier les menaces et mettre en œuvre les défenses appropriées ;</li><li>Gérer les accès et les privilèges appropriés.</li></ul></li><li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.<ul><li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique.</li></ul></li><li>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1d8d17e7 e-con-full e-flex e-con e-child" data-id="1d8d17e7" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-14fd6a56 e-con-full e-flex e-con e-child" data-id="14fd6a56" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-11debba5 elementor-widget elementor-widget-heading" data-id="11debba5" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1eacb231 e-con-full e-flex e-con e-child" data-id="1eacb231" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-131fee7e elementor-widget elementor-widget-text-editor" data-id="131fee7e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Le logiciel Proxmox (version 8 ou 9), une machine Kali Linux et une machine Debian 12/13 disposant d’un accès à internet.</p><p>Les scripts sont disponibles sur la forge du réseau Certa :</p><p><a href="https://forge.apps.education.fr/reseau-certa/bts-sio/activites-ctf">https://forge.apps.education.fr/reseau-certa/bts-sio/activites-ctf</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-12f2a018 e-con-full e-flex e-con e-child" data-id="12f2a018" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-71b5be78 e-con-full e-flex e-con e-child" data-id="71b5be78" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-26a2e838 elementor-widget elementor-widget-heading" data-id="26a2e838" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5ae2ec35 e-con-full e-flex e-con e-child" data-id="5ae2ec35" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-21c522b elementor-widget elementor-widget-text-editor" data-id="21c522b" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/Activite1-CTF1.pdf" target="_blank" rel="noopener">Activite1-CTF1.pdf</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/Activites_CTF1.zip" target="_blank" rel="noopener">Activites_CTF1.zip</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Corrigé <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/Activites_CTF1_cor.zip" target="_blank" rel="noopener">Activites_CTF1_cor.zip</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-55e835e9 e-con-full e-flex e-con e-child" data-id="55e835e9" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-246e1c2 e-con-full e-flex e-con e-child" data-id="246e1c2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-32af3b4 elementor-widget elementor-widget-heading" data-id="32af3b4" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
				<div class="elementor-element elementor-element-7925ba86 elementor-widget elementor-widget-text-editor" data-id="7925ba86" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>PROXMOX, containers LXC, vulnérabilités, POP, SSH</p>								</div>
				</div>
		<div class="elementor-element elementor-element-ef563b6 e-con-full e-flex e-con e-child" data-id="ef563b6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-c53ed15 elementor-widget elementor-widget-heading" data-id="c53ed15" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Durée <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/23f1.png" alt="⏱" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				<div class="elementor-element elementor-element-4f055f8 elementor-widget elementor-widget-text-editor" data-id="4f055f8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>2 heures</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3f7aade9 e-con-full e-flex e-con e-child" data-id="3f7aade9" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-577f407c e-con-full e-flex e-con e-child" data-id="577f407c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7bcd150d elementor-widget elementor-widget-heading" data-id="7bcd150d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2032291a e-con-full e-flex e-con e-child" data-id="2032291a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5a4f5622 elementor-widget elementor-widget-text-editor" data-id="5a4f5622" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Novembre 2025</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1e79636f e-con-full e-flex e-con e-child" data-id="1e79636f" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-60f98805 elementor-widget elementor-widget-heading" data-id="60f98805" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-53f226fe e-con-full e-flex e-con e-child" data-id="53f226fe" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-279bfc28 elementor-widget elementor-widget-text-editor" data-id="279bfc28" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Damien SCONTRINO, avec la relecture, les tests et les suggestions de Patrice DIGNAN et Apollonie RAFFALLI</p>								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/securisation-des-protocoles-reseaux-activite-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 9: Sécurisation des applications Web Vulnérabilités</title>
		<link>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/</link>
					<comments>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Thu, 19 Jun 2025 15:37:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[authentification]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[identification]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[sniper]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=9566</guid>

					<description><![CDATA[Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="9566" class="elementor elementor-9566">
				<div class="elementor-element elementor-element-66d20fe2 e-con-full e-flex e-con e-parent" data-id="66d20fe2" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-109ff94f e-grid e-con-full e-con e-child" data-id="109ff94f" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-780e2be7 elementor-widget elementor-widget-heading" data-id="780e2be7" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web</h2>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-622f41d8 e-con-full e-flex e-con e-child" data-id="622f41d8" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-a3d6839 e-con-full e-flex e-con e-child" data-id="a3d6839" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2dd24581 elementor-widget elementor-widget-heading" data-id="2dd24581" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné </h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-601a94f2 e-con-full e-flex e-con e-child" data-id="601a94f2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-58231297 elementor-widget elementor-widget-text-editor" data-id="58231297" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class=""><table border="0" width="100%" cellpadding="5"><tbody><tr><td class="reglageContenu">BTS SIO</td></tr></tbody></table></div><div class=""> </div>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-74bc5777 e-con-full e-flex e-con e-child" data-id="74bc5777" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6d227640 elementor-widget elementor-widget-heading" data-id="6d227640" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-9db8b29 e-con-full e-flex e-con e-child" data-id="9db8b29" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-759d0c55 elementor-widget elementor-widget-text-editor" data-id="759d0c55" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Bloc 3 &#8211; Cybersécurité des services informatiques &#8211; SLAM</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-34a378fd e-con-full e-flex e-con e-child" data-id="34a378fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4f06872c e-con-full e-flex e-con e-child" data-id="4f06872c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-698a3d28 elementor-widget elementor-widget-heading" data-id="698a3d28" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation </h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7338c022 e-con-full e-flex e-con e-child" data-id="7338c022" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-186b0270 elementor-widget elementor-widget-text-editor" data-id="186b0270" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Portswigger.net du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.</p><p>Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.</p><p>Dans un premier temps, l&rsquo;étudiant doit comprendre le mécanisme des attaques.</p><p>Dans un deuxième temps, l’objectif est de réaliser des défis à travers des manipulations pratiques.</p><p>Cette neuvième activité concerne les problématiques liées à l&rsquo;identification et l&rsquo;authentification sur u:ne application web. Cette vulnérabilité est classée n°7 dans la classement OWASP 2021.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-29c72dbc e-con-full e-flex e-con e-child" data-id="29c72dbc" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4500daf9 e-con-full e-flex e-con e-child" data-id="4500daf9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-10dded6e elementor-widget elementor-widget-heading" data-id="10dded6e" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Pré-requis</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56ef613b e-con-full e-flex e-con e-child" data-id="56ef613b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-464e5835 elementor-widget elementor-widget-text-editor" data-id="464e5835" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Administration d’un système Linux.</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-69d9fc42 e-con-full e-flex e-con e-child" data-id="69d9fc42" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3206cf30 elementor-widget elementor-widget-heading" data-id="3206cf30" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3b29f42 e-con-full e-flex e-con e-child" data-id="3b29f42" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4771026c elementor-widget elementor-widget-text-editor" data-id="4771026c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-b702bc0 e-con-full e-flex e-con e-child" data-id="b702bc0" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2749ecf3 e-con-full e-flex e-con e-child" data-id="2749ecf3" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-37f645d elementor-widget elementor-widget-heading" data-id="37f645d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3e84b145 e-con-full e-flex e-con e-child" data-id="3e84b145" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-621e6e9 elementor-widget elementor-widget-text-editor" data-id="621e6e9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li>Protéger les données à caractère personnel ;<ul><li>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</li></ul></li><li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.<ul><li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique ;</li></ul></li></ul><p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7dc3cf1a e-con-full e-flex e-con e-child" data-id="7dc3cf1a" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-584469bd e-con-full e-flex e-con e-child" data-id="584469bd" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6b80841b elementor-widget elementor-widget-heading" data-id="6b80841b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f6c46da e-con-full e-flex e-con e-child" data-id="f6c46da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-681c489a elementor-widget elementor-widget-text-editor" data-id="681c489a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Une machine Kali Linux disposant d&rsquo;un accès à internet et du logiciel BurpSuite (disponible sous Windows).</p><p>Sites officiels : <a href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d0a0841 e-con-full e-flex e-con e-child" data-id="d0a0841" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-03fe9c4 e-con-full e-flex e-con e-child" data-id="03fe9c4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-0a489bb elementor-widget elementor-widget-heading" data-id="0a489bb" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1b5c082 e-con-full e-flex e-con e-child" data-id="1b5c082" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-d20d7d8 elementor-widget elementor-widget-text-editor" data-id="d20d7d8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/owasp_activite_9_authentification.pdf">owasp_activite_9_authentification</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp_activite_9_authentificationcorrection.pdf">owasp_activite_9_authentificationcorrection</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-79a9eb41 e-con-full e-flex e-con e-child" data-id="79a9eb41" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5b30f068 e-con-full e-flex e-con e-child" data-id="5b30f068" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2583194c elementor-widget elementor-widget-heading" data-id="2583194c" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-43c88408 e-con-full e-flex e-con e-child" data-id="43c88408" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1ed0370d elementor-widget elementor-widget-text-editor" data-id="1ed0370d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>OWASP, vulnérabilités, identification, authentification, BurpSuite, sniper</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5087b62c e-con-full e-flex e-con e-child" data-id="5087b62c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6eab0261 e-con-full e-flex e-con e-child" data-id="6eab0261" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1d15c967 elementor-widget elementor-widget-heading" data-id="1d15c967" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f90d64d e-con-full e-flex e-con e-child" data-id="f90d64d" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3c555a77 elementor-widget elementor-widget-text-editor" data-id="3c555a77" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>19 Juin 2025</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5cb56c4a e-con-full e-flex e-con e-child" data-id="5cb56c4a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3d5e995 elementor-widget elementor-widget-heading" data-id="3d5e995" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s)</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3e329582 e-con-full e-flex e-con e-child" data-id="3e329582" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-23159e44 elementor-widget elementor-widget-text-editor" data-id="23159e44" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Patrice Dignan, avec la relecture, les tests et les suggestions de Hervé Le Guern.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2a9467d e-flex e-con-boxed e-con e-child" data-id="2a9467d" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
					</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activite-9-securisation-des-applications-web-vulnerabilites/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 8 : Sécurisation des applications Web</title>
		<link>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Wed, 13 Nov 2024 19:42:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[sniper]]></category>
		<category><![CDATA[SSRF]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2001</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6205" class="elementor elementor-6205">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe <em>OWASP </em>(<em>OpenWeb Application Security Project</em>) afin de se familiariser avec les principales vulnérabilités des applications <em>Web</em>.</p>

<p>Chaque activité couvre une problématique spécifique (<em>SQLi</em>, <em>XSS</em>, <em>CSRF</em>…) en référence au top 10 des vulnérabilités décrites par l&rsquo;<em>OWASP</em>.</p>

<p>Dans un premier temps, l&rsquo;étudiant doit comprendre le mécanisme des attaques.</p>

<p>Dans un deuxième temps, l’objectif est de réaliser des défis à travers des manipulations pratiques.</p>

<p>&nbsp;</p>

<p><strong>Cette huitième activité</strong> concerne les problématiques liées aux falsifications de requêtes côté serveur(SSRF – Server Side Request Forgery). Cette vulnérabilité a fait son entrée en 10ème position dans le dernier classement OWASP.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>Protéger les données à caractère personnel&nbsp;;
	<ul>
		<li>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</li>
	</ul>
	</li>
	<li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.
	<ul>
		<li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;</li>
	</ul>
	</li>
</ul>

<p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_8_ssrf.odt</strong><br />Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp_activite_8_ssrf.odt" target="_blank" rel="noopener">Télécharger</a> (1.36 MB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_8_correction_ssrf.doc</strong><br />Corrigé disponible &#8211;<strong> <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp_activite_8_correction_ssrf.doc">owasp_activite_8_correction_ssrf</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, vulnérabilités, SSRF, BurpSuite, sniper								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									13/11/2024								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice Dignan, avec la relecture, les tests et les suggestions de Hervé Le Guern								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-8-scurisation-des-applications-web/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 7: Défauts de configurations de chiffrement</title>
		<link>https://www.reseaucerta.org/owasp-activit-7-dfauts-de-configurations-de-chiffrement/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-7-dfauts-de-configurations-de-chiffrement/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Tue, 07 Nov 2023 19:42:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2005</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF&#8230;) ...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6208" class="elementor elementor-6208">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce C&ocirc;t&eacute; labo a pour objectif d&#39;exploiter la plateforme d&#39;apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vuln&eacute;rabilit&eacute;s des applications Web. Chaque activit&eacute; couvre une probl&eacute;matique sp&eacute;cifique (SQLi, XSS, CSRF&hellip;) en r&eacute;f&eacute;rence au top 10 des vuln&eacute;rabilit&eacute;s d&eacute;crites par l&#39;OWASP.<br />
Dans un premier temps, l&#39;&eacute;tudiant doit r&eacute;aliser les attaques associ&eacute;es &agrave; chaque vuln&eacute;rabilit&eacute;.<br />
Dans un deuxi&egrave;me temps, l&rsquo;objectif est d&rsquo;analyser et de comprendre les codes sources des scripts pr&eacute;sent&eacute;s dans leur forme non s&eacute;curis&eacute;e puis s&eacute;curis&eacute;e en tant que contre-mesure.</p>

<p>Cette septi&egrave;me activit&eacute; concerne les probl&eacute;matiques li&eacute;es &agrave; l&rsquo;absence ou &agrave; la mauvaise configuration des protocoles de chiffrement. Cette vuln&eacute;rabilit&eacute; est en deuxi&egrave;me position dans le dernier classement du top 10 du groupe OWASP.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li>Chiffrement, authentification et preuve ; principes et techniques ;</li><li>Sécurité des applications web : risques, menaces et protocoles.</li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>Prot&eacute;ger les donn&eacute;es &agrave; caract&egrave;re personnel ;
	<ul>
		<li>Identifier les risques li&eacute;s &agrave; la collecte, au traitement, au stockage et &agrave; la diffusion de donn&eacute;es &agrave; caract&egrave;re personnel.</li>
	</ul>
	</li>
	<li>Garantir la disponibilit&eacute;, l&rsquo;int&eacute;grit&eacute; et la confidentialit&eacute; des services informatiques et des donn&eacute;es de l&rsquo;organisation face &agrave; des cyberattaques.
	<ul>
		<li>Caract&eacute;riser les risques li&eacute;s &agrave; l&rsquo;utilisation malveillante d&rsquo;un service informatique ;</li>
	</ul>
	</li>
	<li>Recenser les cons&eacute;quences d&rsquo;une perte de disponibilit&eacute;, d&rsquo;int&eacute;grit&eacute; ou de confidentialit&eacute;.</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Une machine virtuelle ou physique avec Linux comme syst&egrave;me d&rsquo;exploitation ainsi qu&rsquo;un acc&egrave;s &agrave; internet. Sites officiels : https://www.owasp.org et https://portswigger.net/burp/communitydownload</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_7_defauts_de_configurations_de_chiffrement.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp_activite_7_defauts_de_configurations_de_chiffrement.pdf" target="_blank">Télécharger</a> (411.38 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_7_defauts_de_configurations_de_chiffrement.zip</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp_activite_7_defauts_de_configurations_de_chiffrement.zip" target="_blank">Télécharger</a> (787.36 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp_activite_7_defauts_de_configurations_de_chiffrement_corrige.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp_activite_7_defauts_de_configurations_de_chiffrement_corrige.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, vulnérabilités, SSL, TLS								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									07/11/2023								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice Dignan, avec la relecture, les tests et les suggestions de Hervé Le Guern								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-7-dfauts-de-configurations-de-chiffrement/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 6 : Inclusion de fichiers locaux et distants</title>
		<link>https://www.reseaucerta.org/owasp-activit-6-inclusion-de-fichiers-locaux-et-distants/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-6-inclusion-de-fichiers-locaux-et-distants/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Tue, 07 Nov 2023 19:42:00 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite v2021.8.2]]></category>
		<category><![CDATA[LFI]]></category>
		<category><![CDATA[Mutillidae 2.8.75]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[RFI.]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2006</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6209" class="elementor elementor-6209">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.<br />
Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.<br />
Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.<br />
Cette sixième activité concerne l’inclusion de fichiers locaux et distants. Cette faille arrive en 5ième position dans le classement OWASP 2017.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>Protéger les données à caractère personnel ;
	<ul>
		<li>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</li>
	</ul>
	</li>
	<li>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.
	<ul>
		<li>Caractériser les risques liés à l’utilisation malveillante d’un service informatique ;</li>
	</ul>
	</li>
	<li>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec Linux comme système d’exploitation.<br />Sites officiels : <a href="https://www.owasp.org" target="_blank" rel="noopener">https://www.owasp.org</a> et <a href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite_6_inclusion_de_fichiers_locaux_et_distants.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite_6_inclusion_de_fichiers_locaux_et_distants.pdf" target="_blank">Télécharger</a> (529.17 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite_6_inclusion_de_fichiers_locaux_et_distants.zip</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite_6_inclusion_de_fichiers_locaux_et_distants.zip" target="_blank">Télécharger</a> (897.41 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite_6_correction.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite_6_correction.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae 2.8.75, BurpSuite v2021.8.2, vulnérabilités, LFI, RFI.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									07/11/2023								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Hervé Le Guern								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-6-inclusion-de-fichiers-locaux-et-distants/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 5 : Sécurisation des applications web</title>
		<link>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Mon, 10 Jan 2022 12:51:33 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[injection d’entité externe XML.]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2012</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d’exploiter la plateforme d’apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6214" class="elementor elementor-6214">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d’une plateforme d’apprentissage des vulnérabilités des applications Web - Activité 5 : Attaques de type XXE (XML External Entities)</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d’exploiter la plateforme d’apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.<br />
Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.<br />
Dans un premier temps, l’étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.<br />
Cette cinquième activité traite des vulnérabilités de type XXE (XML External Entities). Cette faille arrive en 5ᵉ position dans le classement OWASP 2021.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1. Langage XML.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Sécurité des applications web : risques, menaces et protocoles.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>&nbsp;&nbsp;&nbsp; • Protéger les données à caractère personnel&nbsp;;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.<br />
&nbsp;&nbsp;&nbsp; • Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ◦ Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.<br />
&nbsp;&nbsp;&nbsp; • Assurer la cybersécurité d’une solution applicative et de son développement.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec <em>Linux</em> comme système d’exploitation.</p><p>Sites officiels :<br /><u><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a></u> et <u><a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></u></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.odt</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite5-v1.0.odt" target="_blank">Télécharger</a> (212.04 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite5-v1.0.pdf" target="_blank">Télécharger</a> (239.38 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite5-v1.0.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite5-v1.0.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR, injection d’entité externe XML.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									10/01/2022								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Valéry Tschaen et Amal Hecker.								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-5-scurisation-des-applications-web/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 4 Brèche sur des informations confidentielles</title>
		<link>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Sat, 07 Nov 2020 12:01:03 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2022</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2022" class="elementor elementor-2022">
				<div class="elementor-element elementor-element-3c7f100d e-con-full e-flex e-con e-parent" data-id="3c7f100d" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-1858d499 e-grid e-con-full e-con e-child" data-id="1858d499" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-7ce9681 elementor-widget elementor-widget-heading" data-id="7ce9681" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Exploitation d'une plateforme d'apprentissage des vulnérabilités des applications Web
<br><br>Activité 4 : Brèche sur des informations confidentielles
</h2>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1ccf21b5 e-con-full e-flex e-con e-child" data-id="1ccf21b5" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c2c235 e-con-full e-flex e-con e-child" data-id="5c2c235" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-39dd0cd elementor-widget elementor-widget-heading" data-id="39dd0cd" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2ed17df1 e-con-full e-flex e-con e-child" data-id="2ed17df1" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4a3084f9 elementor-widget elementor-widget-text-editor" data-id="4a3084f9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>BTS SIO</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4853e7d9 e-con-full e-flex e-con e-child" data-id="4853e7d9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-538d082f elementor-widget elementor-widget-heading" data-id="538d082f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-226be346 e-con-full e-flex e-con e-child" data-id="226be346" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7d7bea25 elementor-widget elementor-widget-text-editor" data-id="7d7bea25" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Bloc 3 &#8211; Cybersécurité des services informatiques &#8211; SLAM</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7dbdbc9b e-con-full e-flex e-con e-child" data-id="7dbdbc9b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-37862af9 e-con-full e-flex e-con e-child" data-id="37862af9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2df9c65d elementor-widget elementor-widget-heading" data-id="2df9c65d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62b5fb6a e-con-full e-flex e-con e-child" data-id="62b5fb6a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-15efff9 elementor-widget elementor-widget-text-editor" data-id="15efff9" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe <em>OWASP </em>(<em>OpenWeb Application Security Project</em>) afin de se familiariser avec les principales vulnérabilités des applications <em>W</em><em>eb</em>.</p><p>Chaque activité couvre une problématique spécifique (<em>SQLi</em>, <em>XSS</em>, <em>CSRF</em>…) en référence au top 10 des vulnérabilités décrites par l&rsquo;<em>OWASP</em>.</p><p>Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.</p><p>Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p><p><strong>Cette </strong><strong>quatrième</strong><strong> activité</strong> traite des vulnérabilités associées aux brèches sur des informations confidentielles. Cette faille arrive en 3ième position dans le classement <em>OWASP</em> 2017.</p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-35c8dbf0 e-con-full e-flex e-con e-child" data-id="35c8dbf0" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-4f9531d1 e-con-full e-flex e-con e-child" data-id="4f9531d1" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-489e8135 elementor-widget elementor-widget-heading" data-id="489e8135" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Pré-requis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				<div class="elementor-element elementor-element-3ac2d3a2 elementor-widget elementor-widget-text-editor" data-id="3ac2d3a2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1.</p>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-138f560a e-con-full e-flex e-con e-child" data-id="138f560a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-129853f3 elementor-widget elementor-widget-heading" data-id="129853f3" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				<div class="elementor-element elementor-element-82935e6 elementor-widget elementor-widget-text-editor" data-id="82935e6" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li><p>Chiffrement, authentification et preuve ; principes et techniques ;</p></li><li><p>Sécurité des applications web : risques, menaces et protocoles.</p></li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3869c689 e-con-full e-flex e-con e-child" data-id="3869c689" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-7f73f76b e-con-full e-flex e-con e-child" data-id="7f73f76b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-75a263be elementor-widget elementor-widget-heading" data-id="75a263be" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-f7228ab e-con-full e-flex e-con e-child" data-id="f7228ab" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2a94c38c elementor-widget elementor-widget-text-editor" data-id="2a94c38c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li><p>Protéger les données à caractère personnel ;</p><ul><li><p>Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</p></li></ul></li><li><p>Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.</p><ul><li><p>Caractériser les risques liés à l’utilisation malveillante d’un service informatique ;</p></li><li><p>Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</p></li></ul></li></ul>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d5a5945 e-con-full e-flex e-con e-child" data-id="d5a5945" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-49e19d6e e-con-full e-flex e-con e-child" data-id="49e19d6e" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5607877d elementor-widget elementor-widget-heading" data-id="5607877d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2d265094 e-con-full e-flex e-con e-child" data-id="2d265094" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-263b3978 elementor-widget elementor-widget-text-editor" data-id="263b3978" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec <em>Linux</em> comme système d’exploitation.</p><p>Sites officiels :<br /><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-49c0a639 e-con-full e-flex e-con e-child" data-id="49c0a639" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-446a68ca e-con-full e-flex e-con e-child" data-id="446a68ca" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5037c3e8 elementor-widget elementor-widget-heading" data-id="5037c3e8" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-d47a6bb e-con-full e-flex e-con e-child" data-id="d47a6bb" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-590810e4 elementor-widget elementor-widget-text-editor" data-id="590810e4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/Laboratoires/owasp-activite4-v1.0.pdf">owasp-activite4-v1.0</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <a href="https://www.reseaucerta.org/wp-content/uploads/Laboratoires/owasp-activite4-v1.0.odt">owasp-activite4-v1.0</a></strong></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Corrigé : <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp-activite4Correction-v1.0.zip">owasp-activite4Correction-v1.0</a></strong></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-10a92eea e-con-full e-flex e-con e-child" data-id="10a92eea" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-60207579 e-con-full e-flex e-con e-child" data-id="60207579" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7d2df509 elementor-widget elementor-widget-heading" data-id="7d2df509" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-38491628 e-con-full e-flex e-con e-child" data-id="38491628" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-c0a5be4 elementor-widget elementor-widget-text-editor" data-id="c0a5be4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class="">OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR.</div>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7af2e1bc e-con-full e-flex e-con e-child" data-id="7af2e1bc" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-7096989b e-con-full e-flex e-con e-child" data-id="7096989b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-41ed9a6b elementor-widget elementor-widget-heading" data-id="41ed9a6b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5c6fdda5 e-con-full e-flex e-con e-child" data-id="5c6fdda5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1ea52ac6 elementor-widget elementor-widget-text-editor" data-id="1ea52ac6" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<div class="">07 Novembre 2020</div>								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3cd01e04 e-con-full e-flex e-con e-child" data-id="3cd01e04" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-683a1c73 elementor-widget elementor-widget-heading" data-id="683a1c73" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-59c3618c e-con-full e-flex e-con e-child" data-id="59c3618c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2b4b8542 elementor-widget elementor-widget-text-editor" data-id="2b4b8542" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Patrice DIGNAN avec la relecture de Valéry TSCHAEN</p>								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-4-brche-sur-des-informations-confidentielles/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 3 : Vulnérabilités de type XSS</title>
		<link>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Sat, 07 Nov 2020 11:56:11 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite 1.7.29]]></category>
		<category><![CDATA[cyber-sécurité.]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[Mutillidae 2.6.60]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2023</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en réfé...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2023" class="elementor elementor-2023">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications Web - Activité 3: Vulnérabilités de type XSS (Cross Site Scripting)</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 SLAM – Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage Mutillidae du groupe OWASP (OpenWeb Application Security Project) afin de se familiariser avec les principales vulnérabilités des applications Web.<br />
Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.<br />
Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p>

<p>Cette troisième activité traite des vulnérabilités de type XSS (Cross Site Scripting). Cette faille arrive en 7ième position dans le classement OWASP 2017.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Dans l’activité 1, avoir lu la présentation (owasp-presentation-v1.1) et réalisé les installations décrites dans le fichier owasp-mise_en_place-v1.1.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>
	<p>Chiffrement, authentification et preuve&nbsp;; principes et techniques&nbsp;;</p>
	</li>
	<li>
	<p>Sécurité des applications web&nbsp;: risques, menaces et protocoles.</p>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7582c6ed elementor-widget elementor-widget-text-editor" data-id="7582c6ed" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul>
	<li>
	<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Protéger les données à caractère personnel&nbsp;;</span></span></p>

	<ul>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Identifier les risques liés à la collecte, au traitement, au stockage et à la diffusion de données à caractère personnel.</span></span></p>
		</li>
	</ul>
	</li>
	<li>
	<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Garantir la disponibilité, l’intégrité et la confidentialité des services informatiques et des données de l’organisation face à des cyberattaques.</span></span></p>

	<ul>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Caractériser les risques liés à l’utilisation malveillante d’un service informatique&nbsp;;</span></span></p>
		</li>
		<li>
		<p><span style="font-family:Arial,Helvetica,sans-serif"><span style="font-size:10pt">Recenser les conséquences d’une perte de disponibilité, d’intégrité ou de confidentialité.</span></span></p>
		</li>
	</ul>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span style="font-family: Arial,Helvetica,sans-serif;"><span style="font-size: 10pt;">Deux machines éventuellement virtualisées sont nécessaires avec Linux comme système d’exploitation.</span></span></p><p><span style="font-family: Arial,Helvetica,sans-serif;"><span style="font-size: 10pt;">Sites officiels :<br /><a class="western" href="https://www.owasp.org/" target="_blank" rel="noopener">https://www.owasp.org</a> et <a class="western" href="https://portswigger.net/burp/communitydownload" target="_blank" rel="noopener">https://portswigger.net/burp/communitydownload</a> </span></span></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3-v1.0.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite3-v1.0.pdf" target="_blank">Télécharger</a> (764.12 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3-v1.0.odt</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite3-v1.0.odt" target="_blank">Télécharger</a> (942.73 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite3Correction-v1.0.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite3Correction-v1.0.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae 2.6.60, BurpSuite 1.7.29, vulnérabilités, SQLi, XSS, IDOR, cyber-sécurité.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									07/11/2020								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Hervé Le GUERN, Yann BARROT, David ROUMANET, Roger SANCHEZ et Valéry TSCHAEN								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-3-vulnrabilits-de-type-xss/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 2 : authentification et gestion des sessions</title>
		<link>https://www.reseaucerta.org/owasp-activit-2-authentification-et-gestion-des-sessions/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-2-authentification-et-gestion-des-sessions/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Wed, 04 Jul 2018 14:31:10 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[cyber-sécurité.]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[mutillidae]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2037</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae (OWASP) afin de se familiariser avec les principales vulnérabilités des applications web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2037" class="elementor elementor-2037">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d&#039;apprentissage des vulnérabilités des applications web - Activité 2 : Vulnérabilités liées à l’authentification et à la gestion des sessions
</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 &#8211; Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage&nbsp;<strong>Mutillidae</strong>&nbsp;(OWASP) afin de se familiariser avec les principales&nbsp;vulnérabilités des applications web.&nbsp;</p>

<p>Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.&nbsp;<br />
Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p>

<p>Cette <strong>deuxième activité</strong> traite des problématiques d’<strong>authentification et de gestion des sessions</strong>.</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript. Avoir lu la présentation et réalisé les installations nécessaires à l’activité 1.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Activités supports de l’acquisition des compétences</strong></p>

<p><strong>D4.1 – Maintenance d&#039;une solution applicative</strong></p>

<ul>
	<li>A4.2.1 Analyse et correction d&#039;un dysfonctionnement, d&#039;un problème de qualité de service ou de sécurité.</li>
</ul>

<p><strong>Savoir-faire</strong></p>

<ul>
	<li>Programmer un composant logiciel.</li>
	<li>Adapter un composant logiciel.</li>
	<li>Valider et documenter un composant logiciel.</li>
</ul>

<p><strong>Savoirs associés</strong></p>

<ul>
	<li>
	<p>Techniques de sécurisation.</p>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines éventuellement virtualisées sont nécessaires avec Linux comme système d’exploitation.</p>

<p>Site officiel&nbsp;: https://www.owasp.org</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite2-v1.0.pdf</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite2-v1.0.pdf" target="_blank">Télécharger</a> (830.18 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite2-v1.0.odt</strong><br>Fichier libre &#8211; <a href="/wp-content/uploads/laboratoires/owasp-activite2-v1.0.odt" target="_blank">Télécharger</a> (911.35 KB)</p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite2Corr-v1.0.zip</strong><br>Corrigé disponible &#8211; <a href="/wp-content/uploads/laboratoires/private/owasp-activite2Corr-v1.0.zip" target="_blank">Télécharger</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae, BurpSuite, vulnérabilités, SQLi, XSS, IDOR, cyber-sécurité.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.0								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									04/07/2018								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Hervé Le Guern et de Yann BARROT.								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-2-authentification-et-gestion-des-sessions/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OWASP &#8211; Activité 1 : Les injections SQL</title>
		<link>https://www.reseaucerta.org/owasp-activit-1-les-injections-sql/</link>
					<comments>https://www.reseaucerta.org/owasp-activit-1-les-injections-sql/#respond</comments>
		
		<dc:creator><![CDATA[Administrateur Certa]]></dc:creator>
		<pubDate>Tue, 19 Dec 2017 14:51:24 +0000</pubDate>
				<category><![CDATA[_BTS SIO]]></category>
		<category><![CDATA[Bloc 3 - Cybersécurité des services informatiques - SLAM]]></category>
		<category><![CDATA[Côté labo 🧪]]></category>
		<category><![CDATA[BurpSuite]]></category>
		<category><![CDATA[cyber-sécurité.]]></category>
		<category><![CDATA[IDOR]]></category>
		<category><![CDATA[mutillidae]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[vulnérabilités]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://www.reseaucerta.org/?p=2040</guid>

					<description><![CDATA[Ce Côté labo a pour objectif d'exploiter la plateforme d'apprentissage Mutillidae (OWASP) afin de se familiariser avec les principales vulnérabilités des applications web. Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par...]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2040" class="elementor elementor-2040">
				<div class="elementor-element elementor-element-1dbff715 e-con-full e-flex e-con e-parent" data-id="1dbff715" data-element_type="container" data-e-type="container">
		<div class="elementor-element elementor-element-6a9688ca e-con-full e-flex e-con e-child" data-id="6a9688ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
				<div class="elementor-element elementor-element-566fdb94 elementor-widget elementor-widget-heading" data-id="566fdb94" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">Exploitation d&#039;une plateforme d’apprentissage des vulnérabilités des applications web - Activité 1 : Les injections SQL</h1>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-194278ff e-con-full e-flex e-con e-child" data-id="194278ff" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-5c97a0cc e-con-full e-flex e-con e-child" data-id="5c97a0cc" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-1f8167cf elementor-widget elementor-widget-heading" data-id="1f8167cf" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Public concerné <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-58c14bd6 e-con-full e-flex e-con e-child" data-id="58c14bd6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-5228b330 elementor-widget elementor-widget-text-editor" data-id="5228b330" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									BTS Services Informatiques aux Organisations								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-256bdd03 e-con-full e-flex e-con e-child" data-id="256bdd03" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-fa536cc elementor-widget elementor-widget-heading" data-id="fa536cc" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Matière <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4da.png" alt="📚" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-ba30799 e-con-full e-flex e-con e-child" data-id="ba30799" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-119f6587 elementor-widget elementor-widget-text-editor" data-id="119f6587" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Bloc 3 &#8211; Cybersécurité des services informatiques								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3a4160ca e-con-full e-flex e-con e-child" data-id="3a4160ca" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-65ae97da e-con-full e-flex e-con e-child" data-id="65ae97da" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-53de58f0 elementor-widget elementor-widget-heading" data-id="53de58f0" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Présentation <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-62f424b9 e-con-full e-flex e-con e-child" data-id="62f424b9" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-4e06afea elementor-widget elementor-widget-text-editor" data-id="4e06afea" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ce Côté labo a pour objectif d&rsquo;exploiter la plateforme d&rsquo;apprentissage <strong>Mutillidae </strong>(OWASP) afin de se familiariser avec les principales <strong>vulnérabilités des applications web</strong>.&nbsp;</p>

<p>Chaque activité couvre une problématique spécifique (SQLi, XSS, CSRF…) en référence au top 10 des vulnérabilités décrites par l&rsquo;OWASP.&nbsp;<br />
Dans un premier temps, l&rsquo;étudiant doit réaliser les attaques associées à chaque vulnérabilité.<br />
Dans un deuxième temps, l’objectif est d’analyser et de comprendre les codes sources des scripts présentés dans leur forme non sécurisée puis sécurisée en tant que contre-mesure.</p>

<p>Cette première livraison comporte&nbsp;:</p>

<ul>
	<li>un document de présentation,</li>
	<li>un document permettant de mettre en place l’environnement de test,</li>
	<li>une première activité sur les injections, SQL notamment, et sa correction en accès restreint.</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-6a2bf15b e-con-full e-flex e-con e-child" data-id="6a2bf15b" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-3b21d465 e-con-full e-flex e-con e-child" data-id="3b21d465" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-35909b0a elementor-widget elementor-widget-heading" data-id="35909b0a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Prérequis <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a1.png" alt="⚡" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-21c893af e-con-full e-flex e-con e-child" data-id="21c893af" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-357a666e elementor-widget elementor-widget-text-editor" data-id="357a666e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Commandes de base d’administration d’un système Linux, langages PHP et JavaScript.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-2468b14c e-con-full e-flex e-con e-child" data-id="2468b14c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-50002e0b elementor-widget elementor-widget-heading" data-id="50002e0b" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Savoirs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f393.png" alt="🎓" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-24511f59 e-con-full e-flex e-con e-child" data-id="24511f59" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-709d0cf2 elementor-widget elementor-widget-text-editor" data-id="709d0cf2" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Activités supports de l’acquisition des compétences</strong></p>

<p><strong>D4.1 – Maintenance d&#039;une solution applicative</strong></p>

<ul>
	<li>A4.2.1 Analyse et correction d&#039;un dysfonctionnement, d&#039;un problème de qualité de service ou de sécurité.</li>
</ul>

<p><strong>Savoir-faire</strong></p>

<ul>
	<li>Programmer un composant logiciel.</li>
	<li>Adapter un composant logiciel.</li>
	<li>Valider et documenter un composant logiciel.</li>
</ul>

<p><strong>Savoirs associés</strong></p>

<ul>
	<li>
	<p>Techniques de sécurisation.</p>
	</li>
</ul>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1684513d e-con-full e-flex e-con e-child" data-id="1684513d" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-2a81585b e-con-full e-flex e-con e-child" data-id="2a81585b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-57dfdb65 elementor-widget elementor-widget-heading" data-id="57dfdb65" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Compétences <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-27636038 e-con-full e-flex e-con e-child" data-id="27636038" data-element_type="container" data-e-type="container">
				</div>
				</div>
		<div class="elementor-element elementor-element-476f5b46 e-con-full e-flex e-con e-child" data-id="476f5b46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-57f68725 e-con-full e-flex e-con e-child" data-id="57f68725" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7f9fd83f elementor-widget elementor-widget-heading" data-id="7f9fd83f" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Outils <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8afa5d4 e-con-full e-flex e-con e-child" data-id="8afa5d4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-13fc501f elementor-widget elementor-widget-text-editor" data-id="13fc501f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Deux machines, éventuellement virtualisées, sont nécessaires avec Linux comme système d’exploitation.</p>

<p>Site officiel&nbsp;: https://www.owasp.org</p>
								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-5f9a8b1c e-con-full e-flex e-con e-child" data-id="5f9a8b1c" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-6e2c4d8a e-con-full e-flex e-con e-child" data-id="6e2c4d8a" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-7b5e9f2d elementor-widget elementor-widget-heading" data-id="7b5e9f2d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Téléchargements <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e5.png" alt="📥" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-8c1f3e6b e-con-full e-flex e-con e-child" data-id="8c1f3e6b" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-9d4a7c5e elementor-widget elementor-widget-text-editor" data-id="9d4a7c5e" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-presentation-v1.1.pdf</strong><br />Fichier libre &#8211; <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/owasp-presentation-v1.1_1.pdf">owasp-presentation-v1.1</a></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ce.png" alt="📎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite1-v1.1.zip</strong><br />Fichier libre &#8211; <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/owasp-activite1-v1.1_1.zip">owasp-activite1-v1.1</a></p><p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> owasp-activite1Corr-v1.1.zip</strong><br />Corrigé disponible &#8211; <a href="https://www.reseaucerta.org/wp-content/uploads/laboratoires/private/owasp-activite1Corr-v1.1-1.zip">owasp-activite1Corr-v1.1</a></p>								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-7012ba46 e-con-full e-flex e-con e-child" data-id="7012ba46" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-574718d6 e-con-full e-flex e-con e-child" data-id="574718d6" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-73863dd9 elementor-widget elementor-widget-heading" data-id="73863dd9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Mots-clés ﹟</h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-3683f1b4 e-con-full e-flex e-con e-child" data-id="3683f1b4" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6115401d elementor-widget elementor-widget-text-editor" data-id="6115401d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									OWASP, Mutillidae, BurpSuite, vulnérabilités, SQLi, XSS, IDOR, cyber-sécurité.								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-56867941 e-con-full e-flex e-con e-child" data-id="56867941" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-562116c1 elementor-widget elementor-widget-heading" data-id="562116c1" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Version <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="📝" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-1cbb70b2 e-con-full e-flex e-con e-child" data-id="1cbb70b2" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-2fb0a8a4 elementor-widget elementor-widget-text-editor" data-id="2fb0a8a4" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									V1.1								</div>
				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-733aa9fd e-con-full e-flex e-con e-child" data-id="733aa9fd" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
		<div class="elementor-element elementor-element-480ddade e-con-full e-flex e-con e-child" data-id="480ddade" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6463db97 elementor-widget elementor-widget-heading" data-id="6463db97" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Date de publication <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4e6d85c5 e-con-full e-flex e-con e-child" data-id="4e6d85c5" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-6bf9fe6d elementor-widget elementor-widget-text-editor" data-id="6bf9fe6d" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									19/12/2017								</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4a1a1e4c e-con-full e-flex e-con e-child" data-id="4a1a1e4c" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-3485285a elementor-widget elementor-widget-heading" data-id="3485285a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Auteur.e(s) <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></h4>				</div>
				</div>
				</div>
		<div class="elementor-element elementor-element-4f21a5e7 e-con-full e-flex e-con e-child" data-id="4f21a5e7" data-element_type="container" data-e-type="container">
				<div class="elementor-element elementor-element-36af1b3c elementor-widget elementor-widget-text-editor" data-id="36af1b3c" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									Patrice DIGNAN, avec la relecture, les tests et les suggestions de Pierre François ROMEUF et de Yann BARROT.								</div>
				</div>
				</div>
				</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.reseaucerta.org/owasp-activit-1-les-injections-sql/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
