Penetration Testing mailing list archives

Client/Server application that does not authenticate users


From: Brian Erdelyi <brian_erdelyi () yahoo com>
Date: Thu, 12 Aug 2004 06:39:45 -0700 (PDT)

I have recently discovered a client/server application
where the server does not authenticate users prior to
granting them access.  Sadly, this even happens to be
a financial application for equities trading (sales,
trades, oferrings and order management) used by some
very large firms.

How common is it to find applications that don't
authenticate users prior to granting access?


                
__________________________________
Do you Yahoo!?
Yahoo! Mail is new and improved - Check it out!
http://promotions.yahoo.com/new_mail


Current thread: