Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/3/2012
04:34 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

No Exploit Required: How Attackers Exploit Business Logic Flaws

NT Objectives lists the main vectors of attack that exploit not bugs, but weaknesses in an application

Cyberattacks don't always employ exploited vulnerabilities: Sometimes they prey on weaknesses in the business processes of an application -- so-called business-logic flaws.

Web application security software vendor and security-as-a-service provider NT Objectives today released a list of the top 10 business logic attack vectors out there. A business logic flaw, for example, would entail using a simple script to manipulate the results of an online poll, or a shopping cart app with logic errors that allow attackers to bypass authentication and not actually pay for items.

Dan Kuykendall, co-CEO and CTO of NT Objectives, says most Web application security tests can be automated, but testing for business logic flaws must be performed manually by a penetration test. He says his firm has witnessed several breaches that have used a business logic flaw to get hack an organization.

"I don't think there is enough awareness" of these flaws and attacks, Kuykendall says. "The accessibility of Web applications tends to be a little easier to monitor the traffic and to try to exploit them" via these flaws, he says.

The top 10 includes authentication flags and privilege escalations; critical parameter manipulation and access to unauthorized information/content; developer's cookie-tampering and business process/logic bypass; LDAP parameter identification and critical infrastructure access; business constraint exploitation; business flow bypass; and exploiting clients side business routines embedded in JavaScript, Flash, or Silverlight; identity or profile extraction; file or unauthorized URL access and business information extraction; and denial of services (DoS) with business logic.

NT Objectives' Top 10 Business Logic Attack Vectors report is available here for download. "Business logic flaws are difficult to identify and discover. These flaws are unique to each application and must be discovered by manual testing. This paper is intended as a starting point to assist penetration testers with looking for these flaws as a part of their security reviews," according to NT Objectives' report.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/5/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Cybersecurity Spending Hits 'Temporary Pause' Amid Pandemic
Kelly Jackson Higgins, Executive Editor at Dark Reading,  6/2/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13890
PUBLISHED: 2020-06-06
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
CVE-2020-13889
PUBLISHED: 2020-06-06
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
CVE-2020-13881
PUBLISHED: 2020-06-06
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
CVE-2020-13883
PUBLISHED: 2020-06-06
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
CVE-2020-13871
PUBLISHED: 2020-06-06
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.