Many URL authentication and authorization mechanisms make security decisions based on the HTTP verb in the request. Many of these mechanisms work in a counter-intuitive way. This fact, in combination with some oddities in the way that both web and application servers handle unexpected HTTP verbs causes the rules dictated by those mechanisms to be bypassable. This article goes into detail discussing this vulnerability and how the various vendors are affected. What do you think about this attack do you think we should be concerned?. The link for this article located at webappsec is no longer available. . The link for this article located at webappsec is no longer available.. authentication, authorization, mechanisms, security, decisions, based. . LinuxSecurity.com Team
Most, if not all, of corporate web sites are fundamentally insecure. And this insecurity can allow attackers to access databases, delete or change information, and cause absolute chaos with very little effort or technical know how. . . .. Most, if not all, of corporate web sites are fundamentally insecure. And this insecurity can allow attackers to access databases, delete or change information, and cause absolute chaos with very little effort or technical know how. The problem is with web applications. Back in the good old days when companies used the internet for nothing more than hosting an elaborate electronic brochure, there was no threat. The IT guys would have little to do with the process, with the marketing department taking responsibility for outsourcing most of the work to third-party web developers. Well things have changed. The level of interaction through corporate sites is overwhelming, and web applications allow this interaction to take place - whether it be shopping carts, authentication services or money transfers. The link for this article located at VNUNet.com is no longer available. . Business websites often lack robust security measures, allowing cybercriminals to infiltrate systems and alter sensitive information effortlessly.. Web Applications, Corporate Security, Information Access, Security Threat, Data Protection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.