|
Articles
|
|
 |
Access control enforced by presentation layer
Access control enforced by presentation layer
Overview
Enforcing access control in the presentation layer means that the developer does not show...
|
|
06 May, 2008
Views: 290
|
|
 |
Allowing password aging
Allowing password aging
Overview
Allowing password aging to occur unchecked can result in the possibility of diminished password integrity.
...
|
|
06 May, 2008
Views: 289
|
|
 |
Authentication bypass by alternate name
Authentication bypass by alternate name
Resource has multiple names and not all names are enforcing authentication when being accessed.
...
|
|
06 May, 2008
Views: 265
|
|
 |
Comprehensive list of Threats to Authentication Procedures and Data
Comprehensive list of Threats to Authentication Procedures and Data
Background
There is a bewildering array of tricks, techniques, and...
|
|
06 May, 2008
Views: 217
|
|
 |
Empty String Password
Empty String Password
Abstract
Using an empty string as a password is insecure.
Description
It is never appropriate to use an empty string...
|
|
06 May, 2008
Views: 241
|
|
 |
Not allowing password aging
Not allowing password aging
Overview
If no mechanism is in place for managing password aging, users will have no incentive to update passwords in...
|
|
06 May, 2008
Views: 208
|
|
 |
Reflection attack in an auth protocol
Reflection attack in an auth protocol
Overview
Simple authentication protocols are subject to reflection attacks if a malicious user can use the...
|
|
06 May, 2008
Views: 233
|
|
 |
Using password systems
Using password systems
Overview
The use of password systems as the primary means of authentication may be subject to several flaws or...
|
|
06 May, 2008
Views: 198
|
|
 |
Using single-factor authentication
Using single-factor authentication
Overview
The use of single-factor authentication can lead to unnecessary risk of compromise when compared with...
|
|
06 May, 2008
Views: 250
|
|
 |
Hardcoded Password
Hardcoded Password
Abstract
Hardcoded passwords may compromise system security in a way that cannot be easily remedied.
Description
It is...
|
|
06 May, 2008
Views: 232
|
|