Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Millions of users have personal info stolen due to this simple website access error

  • July 31, 2023
Total
0
Shares
0
0
0


Sensitive information belonging to millions of people is being stolen from various websites and web apps all across the Internet every day, experts have warned. 

The common denominator in all these incidents appears to be the existence of insecure direct object references (IDOR). These are flaws that allow people to request sensitive information from a website or web app, without the site checking if the user is allowed to access such information in the first place.

Now, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on IDORs, in a joint security bulletin published with the Australian Cyber Security Centre.

Common flaws

In its announcement, CISA notes that hackers are “frequently” taking advantage of IDOR flaws “because they are common, hard to prevent outside the development process, and can be abused at scale.”

“Typically, these vulnerabilities exist because an object identifier is exposed, passed externally, or easily guessed—allowing any user to use or modify the identifier,” CISA said.

The consequences of these attacks can be quite painful, as they allow threat actors to steal sensitive data such as financial information, health data, or personal files.

This includes incidents such as the 2019 First American Financial security breach (800 million personal files stolen), the Microsoft Teams IDOR flaw discovered in late June 2023, and the two IDOR bugs in Nexx smart home devices found in April 2023. 

Web developers should step up, CISA then states, and implement secure-by-design principles at each step of the development process. That includes incorporating automated code analysis tools that can spot flaws in the code before the apps ever reach the production stage. 

The two organizations also said developers should set up applications “to deny access by default” to make sure the apps perform authentication checks every time someone asks to access or modify any type of sensitive data.

Via: The Register


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Possible Samsung Galaxy S24 Plus benchmark suggests it’s no match for the iPhone 15 Pro

  • July 31, 2023
View Post
Next Article
  • News

Nikon Zf leak suggests exciting retro camera could launch within days

  • July 31, 2023
View Post
You May Also Like
View Post
  • News

Huawei ban reportedly cost BT half a billion pounds, CEO claims

  • September 22, 2023
View Post
  • News

No One Will Save You is the thrilling Hulu sci-fi horror movie you need to watch this weekend

  • September 22, 2023
View Post
  • News

The CMA says Microsoft is taking “necessary steps to address our original concerns” about Activision acquisition

  • September 22, 2023
View Post
  • News

Ubisoft announces The Division 3 in the least exciting way possible

  • September 22, 2023
View Post
  • News

Quordle today – hints and answers for Friday, September 22 (game #606)

  • September 22, 2023
View Post
  • News

The Pixel Fold is now almost entirely repairable as spare parts appear on iFixit

  • September 22, 2023
View Post
  • News

Asus sells the largest microLED monitor ever for a cool $200,000 — but it’s only 4K and a low refresh rate

  • September 21, 2023
View Post
  • News

Facebook now lets you create alt accounts for better privacy and organization

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.