Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Jiwa Financials - Reporting allows execution of arbitrary reports as SQL user with full permissions. |
|---|---|
| Date: | 2 Jun 2006 03:44:17 -0000 |
Secunia security advisory categorises it as "less critical" : http://secunia.com/advisories/20342/ I'm not going to argue with experts - our categorisation of the risk level stays as it is. Original report (which has been edited) claimed it was a remote exploit - this is false, and seems to have only been included in the report for added sensationalism. There is nothing sensational here. The only vulnerability is that an authenticated user may be able to run a Crystal Report which could possibly reveal sensitive information, should they have the skills to construct such a report. Only information at risk is the information contained within the Jiwa database, nothing else - no other SQL database, no files on the filesystem. Bug # 4186 in our system addresses this report redirection vulnerability. As of 5pm, Thursday June 1st, 2006 a patch for this is available for customers and dealers from our website, www.jiwa.com.au. Password encryption is a todo feature logged way before this was reported. No promise was made. My exact words were : "...I don't like to comment on un-released products, as changes are sometimes withdrawn before release, which can result in disappointment. However, I feel some information on where we are heading may do something to at least partially reassure you that we are making changes to the security within the product..." I then went on to cover a number of topics, including password encryption, and provided a URL to our bug tracking database for Robert to see all we were doing in the software. Does a company which does not care provide someone like Robert with a URL to their internal bug tracking database ? Robert, I strongly suggest you remain factual in your reports in future. We will not tolerate vexatious complaints or threats (care for me to quote some of your emails to me, here in a public forum ?).
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | newsfactory Cross Site Scripting & SQL injection, CrAzY . CrAcKeR |
|---|---|
| Next by Date: | [Full-disclosure] [DRUPAL-SA-2006-005] Drupal 4.6.7 / 4.7.1 fixes SQL injection issue, Uwe Hermann |
| Previous by Thread: | newsfactory Cross Site Scripting & SQL injection, CrAzY . CrAcKeR |
| Next by Thread: | [Full-disclosure] [DRUPAL-SA-2006-005] Drupal 4.6.7 / 4.7.1 fixes SQL injection issue, Uwe Hermann |
| Indexes: | [Date] [Thread] [Top] [All Lists] |