Bugtraq mailing list archives
Re: New Whitepaper - "Second-order Code Injection Attacks"
From: Nicolas Gregoire <ngregoire () exaprobe com>
Date: Tue, 02 Nov 2004 23:19:14 +0100
Le lun 01/11/2004 à 18:36, Gunter Ollmann a écrit :
NGS Software is pleased to make available a new whitepaper about second-order code injection attacks.
Class 3 attacks are often met in large corporations where the Web is the standard way (for both internal employées and "clients") to interact with the corporate data. I've seen some webapps audits where : - malicous data can be inserted via the main corporate website by anybody with a valid email - the main processing is done deep in the internal network, through the Intranet - the Intranet *must* (corporate policy) be configured as Fully Trusted in Internet Explorer, allowing the attacker to use, for example, unsigned ActiveX to hack internal machines. Not sanitizing input is bad, but storing it for later processing with different privileges is much worse ... -- Nicolas Gregoire ----- Consultant en Sécurité des Systèmes d'Information ngregoire () exaprobe com ------[ ExaProbe ]------ http://www.exaprobe.com/ PGP KeyID:CA61B44F FingerPrint:1CC647FF1A55664BA2D2AFDACA6A21DACA61B44F
Current thread:
- New Whitepaper - "Second-order Code Injection Attacks" Gunter Ollmann (Nov 01)
- Re: New Whitepaper - "Second-order Code Injection Attacks" Crispin Cowan (Nov 02)
- Re: New Whitepaper - "Second-order Code Injection Attacks" Jeff Williams (Nov 02)
- Re: New Whitepaper - "Second-order Code Injection Attacks" Nicolas Gregoire (Nov 03)
- <Possible follow-ups>
- RE: New Whitepaper - "Second-order Code Injection Attacks" Gunter Ollmann (NGS) (Nov 02)
- RE: New Whitepaper - "Second-order Code Injection Attacks" Gunter Ollmann (NGS) (Nov 05)
- Re: New Whitepaper - "Second-order Code Injection Attacks" Crispin Cowan (Nov 02)