Wednesday
Feb252009
Weak authentication and other publications
Wednesday, February 25, 2009 at 10:32PM
Last month we published a video demo called "Attacking Web Applications with Broken Authentication". This shows a simple web application that relies on a cookie called "userid" for authentication. You might think that very few sites are vulnerable to this issue, but the truth is I came across this issue last year in a rather large European security conference. Some of the local ISPs also have this sort of security flaw.
What the video demonstrates is not just the flaw, but how to automate exploitation of such a flaw with a particular web application security tool. Check out the video below.
Also, (IN)SECURE Magazine was released yesterday so go grab it. Includes my personal views on security incidents and events of last year. Look out for "The year that Internet security failed". Lots of articles look good but the following caught my eye:
Oh .. and here's the video:
[youtube=http://www.youtube.com/watch?v=5ZLmRMLo6HI]
What the video demonstrates is not just the flaw, but how to automate exploitation of such a flaw with a particular web application security tool. Check out the video below.
Also, (IN)SECURE Magazine was released yesterday so go grab it. Includes my personal views on security incidents and events of last year. Look out for "The year that Internet security failed". Lots of articles look good but the following caught my eye:
- Improving network discovery mechanisms
- Scott Henderson on the Chinese Underground
- Playing with Authenticode and MD5 collisions
Oh .. and here's the video:
[youtube=http://www.youtube.com/watch?v=5ZLmRMLo6HI]

