'Anyone…Could Change Anything'


Access overlooked as call center app wrapped as service


Email    print   
January 15, 2008 —  It was a good idea: Get partners to process their own orders on the Web instead of doing the job for them. But when the small firm that provides shipping services for wineries embarked on its first SOA project, the application was nearly derailed by a serious security oversight.

“A horrific vulnerability showed up in the first hour of testing,” said Roger Thornton, co-founder and chief technology officer for application security tool maker Fortify. “Anyone connected to the system could change anything.”

The company, which Thornton did not name, did what many companies do: It took an existing call center application and “wrapped” it as a service. By SOA-enabling the application and making it available to its business-to-business customers—the wineries—the company sought to gain efficiencies. With its customers directly tied in, call center reps would no longer have to field orders that came in by fax and phone, typing in the who, what, when and where pertaining to wine shipments, said Thornton. “There were great business reasons to do [the project].”

But in its enthusiasm, the company failed to think through a crucial security issue: Who gets access to what information, and what changes are they authorized to make? As a result, it inadvertently authorized all of its customers to access and make changes to all account data on the system. In other words, they could view and update their own accounts, as well as those of all of the other customers.

Thornton said the security nightmare was a carryover from the application’s earlier incarnation, which allowed all call center reps to update all customer accounts. That level of access and authorization made sense for an application designed for internal use only, but not for one intended for outsiders, Thornton said. How did the company manage to overlook such a critical issue? “They implemented the application using the WS-Security family of standards,” Thornton said. “That gave them a false sense of security.”

WS-Security is important because it provides a standard way to implement security issues such as access control, authorization and encryption for Web services. But, of course, the standards don’t specify who should get access and update privileges, said Thornton. “So people think: ‘If I implement WS-Security, my system is secure.’”





Share this link: http://sdt.bz/31653
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
Change Manager blends roles of DBAs, developers
Embarcadero's first post-acquisition version of CodeGear's Change Manager aims to combine the activities of developers and database administrators. It can hold numerous schemas in memory and examine the effects of changes on the whole database, among other abilities Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb