Trilight Zone Forum Index Trilight Zone
Privacy & Anonymity is our specialty !
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws

 
Post new topic   Reply to topic    Trilight Zone Forum Index -> Incidents
Author Message
trihub
Sergeant


Joined: 04 Dec 2006
Posts: 180

PostPosted: Thu Aug 27, 2009 1:52 pm    Post subject: WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws Reply with quote

Source: http://www.xiom.com/whid/blog

While we have no public record of an exploit in this case, it seems that the mare discovery of vulnerabilities in sage new SaaS (software as a service) offering created so much damage to classify it as an incident.

Sage is the leading provider of accounting software in the UK and it was about to launch a trendy small business SaaS offering. However as ZDnet reports, serious security flaws were discovered in the public beta and the company has to call off the launch. Who discovered the issues? naturally the competition. Duane Jackson, the CEO of a tiny rival company reported them on his blog.

More than anything, the incident shows how difficult it is for developers to migrate from desktop software to a web based offering. This is a whole new ball game, and security is one of the more difficult issues to adjust to. On the other hand it also shows that on line services are much more exposed to scrutiny, which may result in better security down the line.

As for the technical details, the reports found that the following issues in the application:

* Password displayed in clear text and sent in the request line.
* Remember me is on by default on any login.
* Access to management sections of the site and other users data.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Trilight Zone Forum Index -> Incidents All times are GMT
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group