參考文獻 |
[1] Woo, Hyung-Jin, "Propaganda Wars in Cyberspace: A Content Analysis of Web Defacement Strategies among Politically Motivated Hacker Groups,"In the annual meeting of the International Communication Association, San Diego, CA, May 27, 2003.
[2] Gene H. Kim and Eugene H. Spafford, “Writing, Supporting, and Evaluating Tripwire: A Publicly Available Security Tool,” In Proceedings of USENIX Applications Development Symposium, Toronto, Canada, April 1994.
[3] Da-Wei Lin and Yi-Min Chen, “Dynamic Webpage protection based on Content integrity,” Int. J. Management and Enterprise Development, 2008, Vol. 5, No.1, pp. 63 - 76.
[4] Web Again, http://www.lockstep.com/webagain/index.html
[5] W. Fone and P. Gregory, "Web page defacement countermeasures," In Proceedings of the 3rd International Symposium on Communication Systems Networks and Digital Signal Processing, pages 26–29, Newcastle, UK, July 2002.IEE/IEEE/BCS.
[6] A. Cooks and M. S. Olivier, “Curtailing web defacement using a read-only strategy,” in Proceedings of the 4th Annual Information Security South Africa Conference, Midrand, South Africa, June/July 2004.
[7] A. Bartoli, E. Medvet, "Automatic Integrity Checks for Remote Web Resources," IEEE Internet Computing, vol. 10, no.6, pp. 56-62, Nov/Dec, 2006
[8] Ashish Gehani, Surendar Chandra and Gershon Kedem "Augmenting storage with an intrusion response primitive to ensure the security of critical data," ACM Conference on Computer Communications Security , Taipei, Taiwan, 2006
[9] Hollander, Yona, Prevent Web Site Defacement,
http://www.mcafee.com/us/local_content/white_papers/wp_2000hollanderdefacement.pdf
[10] Hollander, Yona, The Future of Web Server Security,
http://www.mcafee.com/us/local_content/white_papers/wp_future.pdf
[11] Web Site Defacement, http://www.infinityforensics.com/defacement.pdf
[12] R. Dhamija, J. D. Tygar, and M. Hearst, “Why phishing works,” In Proceedings of the SIGCHI conference on Human Factors in computing systems, Montréal, Québec, Canada, April, 2006.
[13] Statistics on Web Server Attacks for 2005 -2007, http://www.zone-h.org/content/view/14928/30
[14] 東森新聞 陳曉藍, 台灣駭客攻擊事件四小龍之冠,90%銀行曾遭入侵http://www.nownews.com/2007/03/08/339-2063921.htm
[15] Netcraft,May 2008 Web Server servey, http://news.netcraft.com/archives/web_server_survey.html
[16] 呂芳懌、楊子逸,“IIS 網頁伺服器Unicode 漏洞探討”,第五屆資訊管理學術暨政資訊實務研討會,警察大學,2001 年,94-100頁。
[17] Microsoft IIS and PWS Extended Unicode Directory Traversal Vulnerability, http://www.securityfocus.com/bid/1806/info
[18] CERT® Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability,
http://www.cert.org/advisories/CA-2002-17.html
[19] Apache Chunked-Encoding Memory Corruption Vulnerability, http://www.securityfocus.com/bid/5033/info
[20] Apache remote exploit, http://www.derkeiler.com/Mailing-Lists/Securiteam/2005-04/0096.html
[21] CERT® Advisory CA-2002-27 Apache/mod_ssl Worm, http://www.cert.org/advisories/CA-2002-27.html
[22] Frédéric Perriot and Peter Szor, An Analysis of the Slapper Worm Exploit, http://www.symantec.com/avcenter/reference/analysis.slapper.worm.pdf
[23] Symeantect, CodeRed worm, http://www.symantec.com/security_response/writeup.jsp?docid=2001-071911-5755-99
[24] Microsoft, Unchecked Buffer in Index Server ISAPI Extension Could Enable Web Server Compromise, http://www.microsoft.com/technet/security/bulletin/MS01-033.mspx
[25] phpBB, howdark.com exploits, http://www.phpbb.com/community/viewtopic.php?f=14&t=240513
[26] US-CERT, phpBB viewtopic.php fails to properly sanitize input passed to the "highlight" parameter,
http://www.kb.cert.org/vuls/id/497400
[27] Symeantect, Perl.Santy.A., http://www.symantec.com/security_response/writeup.jsp?docid=2004-122109-4444-99
[28] Robert Lemos, Net worm using Google to spread, http://news.zdnet.com/2100-1009_22-5499725.html
[29] SQL Injection Walkthrough, http://www.securiteam.com/securityreviews/5DP0N1P76E.html
[30] Microsoft『資料隱碼』SQL Injection的源由與防範之道, http://www.microsoft.com/taiwan/sql/SQL_Injection.htm
[31] 恆逸資訊 胡百敬, SQL Injection (資料隱碼)– 駭客的 SQL填空遊戲(上),
http://www.microsoft.com/taiwan/sql/SQL_Injection_G1.htm
[32] KNOPPIX, http://www.knopper.net/knoppix/index-en.html
[33] Fielding, et al, part of Hypertext Transfer Protocol -- HTTP/1.1 RFC 2616, http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
[34] LinuxQuestions.org,
http://wiki.linuxquestions.org/wiki/Securing_Apache#Dangerous_HTTP
[35] ApacheWeek, Publishing Pages with PUT, http://www.apacheweek.com/features/put
[36] Accessory Scripts,
http://www.w3.org/Daemon/User/Config/Accessories.html#POST-Script
[37] Wikipedia,Web-hosting service,
http://en.wikipedia.org/wiki/Web_hosting
[38] Web Hosting 檔案傳輸,
http://big5.website-solution.net/support_tutorial.html#da
[39] Web Hosting 網頁上傳,
http://www.webhosting.com.hk/menu.php
[40] Windows SharePoint Services,
http://technet.microsoft.com/zh-tw/windowsserver/sharepoint/bb267377
(en-us).aspx
[41] 微軟 IIS 5.0 緩衝區滿溢漏洞,
http://www.hkcert.org/archive/salert/chinese/s030318_win_webdav.html
[42] CVE-2003-0109,
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0109 |