Wednesday December 3, 2008 7:18 AM AEST
Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
Web

Business logic flaws endanger websites

  • Email a Friend
  • Print Page
Business logic flaws endanger websites
By Dan Kaplan
Aug 13, 2008 9:50 AM | 1 Comment
Tags: Business | logic | flaws | endanger | websites
Never mind scanning your website for vulnerabilities in code to prevent attacks.

That may not be enough to protect from another high-risk business impediment: logic flaws. And the potential cost to victim sites could be in the millions.

Two researchers from WhiteHat Security, an application security firm, explained at the Black Hat conference in Las Vegas that business logic flaws often are overlooked by quality assurance teams. Meanwhile, their presence is only expected to grow in coming years.

“Their job is to test what software is supposed to do, not what it is made to do,” said Jeremiah Grossman, founder and chief technology officer of WhiteHat.

The vulnerabilities range in complexity and commonly involve mistakes such as insufficient authorization or predictable resource location.

“They appear completely real,” Grossman said. “There's nothing hacker-ish to them. But people love them [to make money].”

Grossman and Trey Ford, director of solutions architecture at WhiteHat, provided an entertaining look at some of the exploit possibilities, ranging from the somewhat technical to relatively unchallenging.

They included:


  • Reserving a seat while booking a flight online but not paying for the ticket. The seat will remain reserved for a certain period of time so you can grab it when you are ready to pay.

  • Developing a simple script that allows you use thousands of e-coupons or using a similar script to open thousands of brokerage accounts that can each receive small deposits from a bank – usually around five cents – to verify transactions. In the end, you could end up making tens of thousands.

  • Stuffing cookies into other websites to receive payments by advertising affiliates.

  • Guessing the URLs of press releases announcing the earnings of a particular public company, prior to their official release.



“The more technical, the more complex, the more overhead – the more chance of getting caught,” Ford said. “There are some very profitable ways to do these attacks without any of that.”

Among the easiest-to-execute scams took advantage of a business logic flaw on the QVC.com website. A Georgia woman figured out that if she placed an order and canceled it by a certain time, the items would still be shipped to her but she wouldn't have to pay.

To monetize the scheme, she sold the items on eBay, turning more than a US$400,000 profit. Authorities eventually caught on because she got lazy and shipped the items still in their QVC packaging – so customers contacted the television shopping network if they had a problem.

She was found guilty of wire fraud last October.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
I am Jr.Scientist at Victoria UNiversity of Wellington , i have identified this Vulnerability in the web application in 2004 , my research paper Published in the INternational Journal of Computers & Security. Title is:Secure business application logic for e-commerce systems Faisal Nabi http://tinyurl.com/5p29xt This research will help the e-commerce web system designers designing applications logic securely. I am currently working in the same area.
SC Magazine - comments icon Posted by Dr.Faisal NabiAug 13, 2008 2:40 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers