Daily using/supporting

Get Firefox browser!
Get Thunderbird!
Get Opera browser!
Get The Gimp!
Get Inkscape!
Get LibreOffice!
Get Videolan!
Get Linux!
Get Mandriva!
Get Joomla!
Hacker Emblem

Archives

Which topics would you like us to cover more?

Latest comments

Latest tweets

about 1 day ago Using REDIPS.drag to add drag and drop to your .Net webapplication #li #dib0 http://t.co/n8zY3s7d
about 7 days ago http://t.co/cknQcDbo #Kindle
about 15 days ago Freedom isn't the ability to choose what to do or say, but the ability to choose what not to do or say #freedom
about 29 days ago http://t.co/61KTQknI #Kindle
12 Apr 2012 Force the use of a networking adapter using C# #li #dib0 http://t.co/ZTJOPzOz
9 Apr 2012 Mandriva 2010.2 and USB devices in Virtualbox http://t.co/fwq9gbHB
9 Apr 2012 Execute a http request to you own site with PHP http://t.co/DIvWPrpd
Home Architecture, security and coding The results of a pentest
The results of a pentest
Written by 0na   
Thursday, 03 March 2011 19:47

We recently performed a penetration test on a website. The outcome was not shocking but actually very interesting to me.
I noticed one small thing that I'll try to explain.

The website contains a public and a closed part. The sensing part is an application inside the website.
This is an easy way if you want to use the same application on more websites. Now we've done our best to secure the sensing part.
The login part goes over SSL and we have more secrets:) The links on that sensed part of the site are included by a CMS. So far so good. But nothing seems to be as you think it is...The links are absolute, including a complete protocol which is the HTTP protocol. Don't forget in a HTTPs environment.

What's my point of this story. That this can happen is not very shocking. Bigger fish with more commercial interest have run into this kind of thoughtlessness. It's obvious and I'm convinced that security is not something reserved only to the technical guys.
Knowledge is the key..... train people.

 

Add comment


Security code
Refresh

If the human brain was simple enough for us to understand we'd be so simple we couldn't understand. - Unknown


© 2009 - 2012, Division by Zero

Template based on the empire template by joomlashack 

Valid XHTML 1.0 Strict  Valid CSS!  Creative Commons License
This work by Division by Zero is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Netherlands License.