Get a Pentest and security assessment of your IT network.

News

Poor server validation: Letting the thief in through the front door

The client was identifying (and authenticating) the server with pieces of information that can be easily spoofed. The client applications would check with the server periodically to see if there were any new updates to be installed. If new updates were available the client would download them and install them on the client machine. The solution to this problem is to make decisions based on non-spoofable information such as a signature. Using popular digital signature techniques you can securely verify a host is who they say they are.”]

Source: https://www.csoonline.com/article/2136906/poor-server-validation–letting-the-thief-in-through-the-front-door.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks