Penetration Testing mailing list archives
Client/Server application that does not authenticate users
From: Brian Erdelyi <brian_erdelyi () yahoo com>
Date: Thu, 12 Aug 2004 06:39:45 -0700 (PDT)
I have recently discovered a client/server application where the server does not authenticate users prior to granting them access. Sadly, this even happens to be a financial application for equities trading (sales, trades, oferrings and order management) used by some very large firms. How common is it to find applications that don't authenticate users prior to granting access? __________________________________ Do you Yahoo!? Yahoo! Mail is new and improved - Check it out! http://promotions.yahoo.com/new_mail
Current thread:
- Client/Server application that does not authenticate users Brian Erdelyi (Aug 12)
- RE: Client/Server application that does not authenticate users Dinis Cruz (Aug 16)
- <Possible follow-ups>
- RE: Client/Server application that does not authenticate users Brian Erdelyi (Aug 16)
- RE: Client/Server application that does not authenticate users Dinis Cruz (Aug 16)
- RE: Client/Server application that does not authenticate users Dinis Cruz (Aug 16)