Security Insight

SERVICE – INADEQUATE PERMISSION VALIDATION

Vulnerability examples   Inadequate authorization checks gaps/weaknesses that allow unauthorized users to view, modify, or delete sensitive information without going through a valid authentication process when submitting a request to a website. For example, when you edit an article on an ad, the following HTTP request is sent. The website creates a unique profile for each […]

SERVICE-OPEN SOURCE FILE UPLOAD VULNERABILITY

Vulnerability example    Web sites use open source tools to help manage and edit web files. Since the code is open source, security vulnerabilities can also be easily discovered, Therefore, developers/individuals need to be careful when using open source because security is open to all.   Once an attacker has confirmed that an open source library

COMMAND INJECTION IN MOBILE AND IOT

Vulnerability examples    Many IoT devices such as dual-mode routers, IP cameras, and door locks provide their management services, such as providing information or changing settings, through web pages using HTTP. These management pages come from CGI files that are already compiled into the firmware. These CGI files, when needed as specific inputs in the

SQL INJECTION IN CMS

Vulnerability Examples   SQL injection is an attack technique in which an attacker exploits security vulnerabilities toinject and execute arbitrary SQL statements, thereby manipulating the database to performabnormal operations. There are attack types such as Error SQL Injection, Blind SQLInjection, and Union based SQL Injection.    For example, in the code in the figure below, the

CROSS SITE SCRIPTING IN CMS

   Cross-site scripting (XSS) is an attack method that contains malicious scripts on a web page and is placed on the user’s side. For example, if an unverified external input value is used to create a dynamic web page, visitors to that web page will immediately see the attacker’s identity and information about the target web

OVERFLOW IN APPLICATION

Vulnerability Examples:   An overflow vulnerability occurs when a program that uses contiguous memory space triesto read or write data to a location beyond the allocated memory range. By causing programmalfunction or executing malicious code, an attacker gains the authority to control theprogram.   Most of the vulnerabilities are caused by copying into memory without verifying the

COMMAND INJECTION IN APPLICATION

Vulnerability Examples:    Command Injection is a vulnerability in which unintentional system commands are executed by user input values that have not undergone proper verification procedures, which can inappropriately change user privileges or adversely affect system operation and operation.    For example, when the program is executed as shown in figure below, a specific string

FILE DOWNLOAD IN ACTIVE X

Vulnerability Examples:   File download and execution vulnerabilities refer to weaknesses that arise from the capabilityof ActiveX to download external files. These methods are typically employed to executefunctions within ActiveX or to substitute a specific module. When a file is downloaded, theexternal server, file name, and local save path are provided as argument values.    As

HOW TO STRATEGICALLY PREPARATE THE DPP LAW

Understanding The DPP Law     In the digital age, data protection has become a paramount concern for both businesses and individuals. Rwanda, cognizant of these shifting paradigms, introduced the Data Protection and Privacy (DPP) Law, setting standards and guidelines for businesses operating within its jurisdiction. Ensuring compliance with this comprehensive regulation is not just a