Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Privacy » Insufficient Authentication - How attackers access sensitive content

Insufficient Authentication - How attackers access sensitive content

Category: Privacy
Published: 02/02/2007, 11:56  
Editor: Security Software Zone
 
Print article
Send to a friend
Search in reviews

Web-based admin tools are a good example of web sites providing access to sensitive functionality. Depending on the specific online resource, these web applications should not be directly accessible without the user required to properly verify their identity. To get around setting up authentication, some resources are protected by "hiding" the specific location and not linking the location into the main web site or other public places. However, this approach is nothing more than "Security Through Obscurity".

Its important to understand that simply because a resource is unknown to an attacker, it still remains accessible directly through a specific URL. The specific URL could be discovered through a Brute Force probing for common file and directory locations (/admin for example), error messages, referrer logs, or perhaps documented in help files. These resources, whether they are content or functionality driven, should be adequately protected. Example Many web applications have been designed with administrative functionality location directory off the root directory (/admin/). This directory is usually never linked to anywhere on the web site, but can still be accessed using a standard web browser.

Since the user or developer never expected anyone to view this page since its not linked, adding authentication is many times overlooked. If an attacker were to simply visit this page, they would obtain complete administrative access to the web site.

Bookmark to:
Add 'Insufficient Authentication -  How attackers  access sensitive content' to Del.icio.us Add 'Insufficient Authentication -  How attackers  access sensitive content' to digg Add 'Insufficient Authentication -  How attackers  access sensitive content' to FURL Add 'Insufficient Authentication -  How attackers  access sensitive content' to reddit Add 'Insufficient Authentication -  How attackers  access sensitive content' to Technorati Add 'Insufficient Authentication -  How attackers  access sensitive content' to Yahoo My Web Add 'Insufficient Authentication -  How attackers  access sensitive content' to Stumble Upon Add 'Insufficient Authentication -  How attackers  access sensitive content' to Google Bookmarks Add 'Insufficient Authentication -  How attackers  access sensitive content' to RawSugar Add 'Insufficient Authentication -  How attackers  access sensitive content' to Squidoo Add 'Insufficient Authentication -  How attackers  access sensitive content' to Spurl Add 'Insufficient Authentication -  How attackers  access sensitive content' to Netvouz Add 'Insufficient Authentication -  How attackers  access sensitive content' to Rojo Add 'Insufficient Authentication -  How attackers  access sensitive content' to Bloglines Add 'Insufficient Authentication -  How attackers  access sensitive content' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Insufficient Authentication - How attackers access sensitive content
 

BitGravity Presents Industry’s First Integrated Security Suite
 The pioneer in Content Delivery Networks (CDN) for interactive broadcasting, BitGravity, Inc., announced a suite of products that offers Internet media properties the ability to protect their copyrighted content from the growing number of pirating technologies without disruption to the customer experience, called BG Secure.
Read More >
04/15/2008, 13:50
 

New peripherals to secure multi-user home personal computers, small-medium business and government PCs - BioCert® PCLokR
 The new device has been released recently by a leading global supplier of fingerprint security devices.
Read More >
09/04/2007, 21:48
 

Intellitactics Security Manager is One of The Few Vendor Products Selected by Security University for Their Sold out Training Event at Black Hat in Las Vegas
 The software solution is a comprehensive security management product for strengthening enterprise defenses.
Read More >
07/30/2007, 13:11
 

Federal Trade Commission's Online ID Theft Complaint Form is Vulnerable to Keylogger Attacks
 A warning about the personal information submitted via the Federal Trade Commission's online ID Theft Complaint Form.
Read More >
04/06/2007, 18:12
 

Sharp and DocuLex Secures 'Instant Document Access'
 The validation of DocuLex Archive Studio 4's seamless integration with Sharp® MFPs via Sharp OSA™ technology was announced by creators of electronic document management software, DocuLex (http://www.doculex.com).
Read More >
05/14/2008, 10:53

Sponsored