Web Perversion
Solutions
Inside Sanctum
Events
Customers
Support and Training
AppShield Demo
AppScan Demo
web perversion demo
Press Release Back to Press Releases
Perfecto Technologies Black Watch Labs Advisory Reveals Vulnerability in Lotus Domino Login
 

Santa Clara, Calif. - May 19, 2000 - Perfecto Technologies, the leading developer of Web application security management software, today released its latest Black Watch Labs advisory that reveals how Lotus Domino provides elaborate and rich Access Control Lists (ACLs) that control the access of objects, e.g. web pages. Some applications, however, do not employ ACLs properly, and rely on a successful user log-in procedure as the only security measure for protection against illegal access. Such mechanism can be easily bypassed, and the web pages can be viewed by an unprivileged user.

Suppose that the application has page A (which should be world readable), with a link to page B, which should be readable only to privileged users. Also suppose that this application is not properly configured, that is, both A and B are viewable to the anonymous web user (with respect to their ACLs). Finally, the link from A to B is such that it pops-up a log-in window (this is done by appending a "&login" to the link). The application seems to require a valid log-in before accessing the privileged page B, and indeed, failure to provide a valid log-in results in an error-page, rather than page B. However, it the attacker inspects the link from A to B, and manually removes the "&login", and then requests this link (i.e. attempts to access page B), then this attacker's request is granted, and page B is presented to him/her. It should be stressed that the attacker did not bypass the ACL mechanism provided by Lotus Domino. The problem is that the application falsely assumed that the login phase is mandatory for accessing page B, although page B's ACL allows all possible users to view it; where in fact, the "&login" parameter cannot force the user to actually undergo the login phase, and Lotus Domino does not enforce going through a login phase in order to get the next page. For more information go to https://www.perfectotech.com/blackwatchlabs/.

About Black Watch Labs (www.perfectotech.com/blackwatchlabs/)
Black Watch Labs is a research group operated by Perfecto Technologies Inc., the leader in Web Application Security Management. Black Watch Labs was established in order to further the knowledge of the Internet community in the arena of Web application security management. Black Watch Labs publishes security advisories regularly, which are maintained at https://www.perfectotech.com/blackwatchlabs/, and are also posted to relevant security lists and Web sites. Black Watch Labs also operates a Web application security mailing list, which can be subscribed to at https://www.perfectotech.com/blackwatchlabs/. For more info about Black Watch Labs and Web Application Security Management, please call (408) 352-2000 or email [email protected].

About Perfecto Technologies
Founded in 1997 and headquartered in Santa Clara, Calif., Perfecto Technologies is the leader in Web Application Security Management software. AppShield, Perfecto Technologies flagship product, is the first to provide extreme security for customer-facing applications in dynamic Web site environments. Perfecto Technologies has customers in many sectors including, banking, e-tailing, finance, government and healthcare. Privately held, Perfecto Technologies is funded by blue-chip venture capital firms and industry leaders, including Sequoia Capital, Walden and Intel Corporation. More information about Perfecto Technologies may be obtained by visiting the Company's Web site at www.perfectotech.com or by calling the Company directly at (408) 352-2000.

 #   #   #

For Immediate Release
Contact:

Diane Fraiman
Perfecto Technologies, Inc.
(408) 352-2000
[email protected]

Kevin Pedraja
Sterling Communications
(408) 441-4100
[email protected]

Back to Press Releases


      © 2002 Sanctum, Inc.      Privacy Statement



  1. https://www.gustudentassociation.org/
  2. https://kimmerestaurant.com/
  3. https://www.nyonyafood.com/
  4. https://www.perfectotech.com/
  5. https://www.planetgapyear.com/
  6. https://whatcomvet.com/
  7. https://theclassicyachtexperience.com/
  8. https://www.batonrougerosesociety.org/
  9. https://www.finburysullivan.com/
  10. https://mikrofinanzinstitut.com/
  11. https://oakgroveplantationsc.com/
  12. https://www.the-vision-of-harmony.org/
  13. https://www.pantheonpress.com/
  14. https://thefinancialgraduate.com/
  15. https://www.thenutkitchen.com/
  16. https://altiboutique.com/
  17. https://ambushsweden.com/
  18. https://goingonforgod.com/
  19. https://lasdopestattorney.com/
  20. https://www.sewardne.com/
  21. https://www.tehranfestival.com/
  22. https://www.bistrotmarin.com/
  23. https://brysonchristianmontessorischool.com/
  24. https://www.excalibureurope.com/
  25. https://www.tropicaltopless.com/
  26. https://www.originallotsoflox.com/
  27. https://www.wavespace-berlin.com/
  28. https://www.nicolasboutruche.com/
  29. https://www.michiganmediates.org/
  30. https://www.victoria-abbott.com/
  31. https://www.yourmyrtlebeachproperty.com/
  32. https://metrcconference.com/
  33. https://biotechscope.com/
  34. https://jzbrasil.com/
  35. https://kingswoodacquisition.com/
  36. https://www.mobilegourmetkitchen.com/
  37. https://saafootball.org/
  38. https://griefergames.info/
  39. https://ampalauragarcianoblejas.com/
  40. sbobet
  41. judi parlay
  42. togel kamboja
  43. Pengeluaran Cambodia
  44. judi bola
  45. demo slot
  46. Togel Kamboja
  47. keluaran Kamboja
  48. slot thailand
  49. togel kamboja
  50. keluaran kamboja
  51. togel Kamboja
  52. slot demo
  53. keluaran cambodia
  54. togel cambodia
  55. demo mahjong
  56. live draw macau
  57. slot thailand
  58. pengeluaran kamboja
  59. judi bola
  60. sbobet
  61. slot demo
  62. togel sdy