Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Client/Server application that does not authenticate users

Client/Server application that does not authenticate users

From: Brian Erdelyi <brian_erdelyi_at_yahoo.com>
Date: Thu, 12 Aug 2004 06:39:45 -0700 (PDT)

I have recently discovered a client/server application
where the server does not authenticate users prior to
granting them access. Sadly, this even happens to be
a financial application for equities trading (sales,
trades, oferrings and order management) used by some
very large firms.

How common is it to find applications that don't
authenticate users prior to granting access?

                
__________________________________
Do you Yahoo!?
Yahoo! Mail is new and improved - Check it out!
http://promotions.yahoo.com/new_mail
Received on Aug 12 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos