Security... What security?

( ) 04/30/05 9:16 PM RSS Leave a Comment »
by Michael

One of the things I do for the company is review the security of new Internet-enabled programs we want to use and establish security procedures for using them.

Earlier this year, I was asked to install a new version of a multi-user CRM (Customer Relationship Management) software that our business sales team would be using (and which I cannot name for you yet). It was a good thing I was involved in this...

You can download the client software for this database from company's web site, but you have to know a user name and password in order to connect to your database of customer data. It turns out that, if you know a user name, but get the password wrong, it will offer to send the password by email to the user's email address. Now, this is a bit of a security concern since email is not usually very secure. However, it was even worse than that...

I noticed that my own computer was sending out the email using my email server settings. So, if I was a "bad guy", I could just set my email settings on my computer to send to my own mail server and retrieve the password from the email sitting on my own server, or I could use a network "sniffer" on my own network to look at the email as it's sent out by my computer.

Even worse, if I don't have a valid password, how does the password get from the server to my computer so it can email it? Obviously, there is some way that the server allows passwords to be retrieved without knowing any passwords.

Needless to say, I classified this program as "trivial security". So far, the company that wrote the program hasn't returned my phone call about the problem, so I am preparing an official "security disclosure" to send to them and subsequently to a network security mailing list. It's a bit of work to write, but it's the right thing to do so that companies that don't do this kind of security analysis might know about this significant issue.

If only the software company had spent the time getting it right in the first place. :-)

  1. I think its great that you are pursuing this. If the developer won't take it seriously perhaps they will when they receive their first published exploit warning on a site like securiteam. Can't say you didn't try to bring this to their attention...

    Comment by Chris — 05/01/2005 11:20 PM

Leave a comment (TrackBack)

(plain text or HTML: you can (optionally) use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong> )

Powered by... WordPress

horace andy and patrick andy tom and jerry richard shindell farnelli vs zi-ko heaven http://aciteglegrife.com/ simon reverb I like this! blog mp3 share here bombasteg for svasteg You are viewing Navigate Payments imdb fans golden b.c. greger hillman funky groove Fallout 3 free download free software downloads Ne kirzachi, no mp3