Skip to main content

Posts

Showing posts from March, 2014

Password reset feature in single user, isolated environment applications

I came across one application while doing security assessment and found that they were using default admin account.And that too the admin account was having credentials as admin:admin. Catastrophic, isn't it? I raised this issue before completing the assessment with the developers. They had their usual excuse- this was introduced to help user reset their passwords through the web application and since the web application was supposed to be used by singles user. It was essentially a single user environment. The web application was running locally on their individual laptops and the laptop was being plugged on the LAN just for few moments to reset some device readings. Now the risk was: Even a momentarily the laptop was connected to local network, the default admin account's presence was known to every other user. If they change the password using the default account then? Though this was single user environment and only very few users were supposed to use the application o