VoteStand is not secure
POST http://votestand.firstandthird.com/api/user?apikey=v0t3st4nd HTTP/1.1
Host: votestand.firstandthird.com
Content-Type: application/json;charset=UTF-8
Origin: file://
Connection: keep-alive
Proxy-Connection: keep-alive
Accept: application/json, text/plain, /
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 10_1_1 like Mac OS X) AppleWebKit/602.2.14 (KHTML, like Gecko) Mobile/14B100 (4297108912)
Accept-Language: en-us
Accept-Encoding: gzip, deflate
Content-Length: 36
{"name":"foo","email":"bat@bar.com"}
In short this application ticks none of the corners of the confidentiality, integrity, or availability (CIA) triad and any data which comes from the app cannot be trusted. Further, every user who downloaded it, registered, and used it should expect that their information could have been exposed and due to the nature of the flaw there is no way that Gregg Phillips can say it wasn't because the application itself suffers from a complete lack of security controls.
0 comments
[ 2.1 ms ] story [ 6.8 ms ] threadNo comments yet.