12.07.2015 Views

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Application Penetration Test for Super Veda- Sample Report -4 SUMMARY OF RESULTSThe penetration test uncovered a number of serious vulnerabilities thatjeopardize the security of individual accounts as well as the security of theapplication's internal network. Following is a short summary of majorvulnerabilities:4.1 READING THE ENTIRE DATABASE CONTENTSSeverity: CriticalAn attacker can alter the address of some of the application web pages insuch a way that enables him to query the internal database for all itsinformation. As a result, the attacker can steal the entire collection ofinformation within the database, which includes all the registeredusernames, passwords, and credit card numbers. The attacker cangenerally be granted access to all the information in the database using amanipulation on the input of an SQL query.4.2 UNAUTHORIZED ACCESS TO ACCOUNTSSeverity: CriticalAn attacker can access accounts of all individual users without priorknowledge of their password, thus bypassing the application'sauthentication.4.3 OBTAINING A DISCOUNT FOR PURCHASESSeverity: HighAn attacker can manipulate the values of a cookie stored on his client inorder to mislead the application into believing that his privileges are higherthan they actually are, thus resulting in his obtaining a discount for hispurchases.ImpervaPage10 of73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!