Recent Posts
- 3.6 billion gallons per day
- China's new slogan
- India's lessons of high energy costs
- Risks of wireless pioneering
- Has oil peaked?
- Fighting global warming like sheep
- Go to a virtual trade show & conference
- Happy World Environment Day!
- Airlines struggle with fuel cost too
- GM acknowledges painful reality
Recent Comments
- Patrick Rafter on Go to a virtual trade show & conference
- Bubba210 on Where your gas money goes
- Mark on GM acknowledges painful reality
- Qukler on I am not a socialist
- rich merritt on I am not a socialist
Most Commented On
- Chinese pharma plants go un-inspected? (2)
- I am not a socialist (2)
- GM acknowledges painful reality (1)
- Go to a virtual trade show & conference (1)
- Where your gas money goes (1)
Archives
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
Blog
Building security around poor programs
November 9, 2007
Last Tuesday I posted a story about a woman who found a hole in an online shopping program that she exploited for her own fun and profit. I asked several cyber security experts to offer an their viewpoints on the matter. Here's the first one, from Todd Nicholson, Industrial Defender:
"We view this more of an internal accounting and process breakdown than a specific cyber security hacking attempt. Clearly the shopper discovered an open loop in the online transaction process that enabled her to place orders without paying for them which is a very scary situation for online merchants but it is highly unlikely that a security system would be able to protect against the type of flaw or vulnerability that caused this incident. Proper application testing and validation of the online ordering application should have provided visibility into this issue. Also QVC accounting and auditing processes should have detected an anomaly in these transactions."
True, this is not hacking in the traditional sense. Ms. Moore-Perry simply took advantage of a program anomoly that was presumably open to anyone who made the same discovery. (We have no way of knowing if others found the same opening.) Todd's point about proper application testing and validation is well made. Programs in the industrial arena should also be subjected to thorough testing to make sure the code is sound before applying security protocols.
The SANS Instutute offers courses on secure code writing. Here's an example.
Posted by Peter Welander on November 9, 2007 | Comments (0)



