Security... What security?

( ) 04/30/05 9:16 PM RSS Leave a Comment »
by Michael

One of the things I do for the company is review the security of new Internet-enabled programs we want to use and establish security procedures for using them.

Earlier this year, I was asked to install a new version of a multi-user CRM (Customer Relationship Management) software that our business sales team would be using (and which I cannot name for you yet). It was a good thing I was involved in this...

You can download the client software for this database from company's web site, but you have to know a user name and password in order to connect to your database of customer data. It turns out that, if you know a user name, but get the password wrong, it will offer to send the password by email to the user's email address. Now, this is a bit of a security concern since email is not usually very secure. However, it was even worse than that...

I noticed that my own computer was sending out the email using my email server settings. So, if I was a "bad guy", I could just set my email settings on my computer to send to my own mail server and retrieve the password from the email sitting on my own server, or I could use a network "sniffer" on my own network to look at the email as it's sent out by my computer.

Even worse, if I don't have a valid password, how does the password get from the server to my computer so it can email it? Obviously, there is some way that the server allows passwords to be retrieved without knowing any passwords.

Needless to say, I classified this program as "trivial security". So far, the company that wrote the program hasn't returned my phone call about the problem, so I am preparing an official "security disclosure" to send to them and subsequently to a network security mailing list. It's a bit of work to write, but it's the right thing to do so that companies that don't do this kind of security analysis might know about this significant issue.

If only the software company had spent the time getting it right in the first place. :-)

  1. I think its great that you are pursuing this. If the developer won't take it seriously perhaps they will when they receive their first published exploit warning on a site like securiteam. Can't say you didn't try to bring this to their attention...

    Comment by Chris — 05/01/2005 11:20 PM

Leave a comment (TrackBack)

(plain text or HTML: you can (optionally) use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong> )

Powered by... WordPress

http://blekly.net/ Blog in Blog some cut mp3
every mp3 time touch we adult mature video woman xxx real r kelly sex tape gay marriage laws in europe http://g-teen.co.cc/latest so what miles davis mp3 http://tomymp3.com/ http://glasshok.com/ http://glasshok.com/1517446/ http://glasshok.com/1517448/ http://glasshok.com/1517451/ http://glasshok.com/1517454/ http://glasshok.com/1517465/ xxx nineteen lesb my home Blog hot blog escort mature in london plavi orkestar odlazim mp3 bitch bury dig ditch artica myspace.com site sonata Arsis- We Are The Nightmare(video Version 1 And 2) face pic adult mpeg daisy foxxx ferrara gay nation army white strips com adult diaper wear genital pleasure bride nude voyeur strip drm douleur faciale keira knightly long nipples xxx sick adult novelty shirt t disney gay pride embarazos tumores vaginales sex orgasmo page ass fucked getting phat white sex theater victoria silvstedt pantyhose miss parker spanking naked lady sex kyla pratt sexy skin tight jeans woman sussex fuck trailer dick cheney gaymovielists nanga bollywood sex fiction gay muslim culture about sex sex cams.com api strip hardcore discount pagan pussy chinese mature clip from inuyasha kagome lisa lol nude adult blooper videos porn for mp4 sexy guys with abs porn junky black celebrity man screensaver sexy