Course Hero Logo

M7A2 Lab.docx - 1 M7A2 Lab: Designing the Secure Database...

Course Hero uses AI to attempt to automatically extract content from documents to surface to you and others so you can study better, e.g., in search results, to enrich docs, and more. This preview shows page 1 - 3 out of 4 pages.

1M7A2 Lab: Designing the Secure DatabaseChristapher M. BessExcelsior CollegeCYS470Laurel Schneider20 June, 2021
2I will identify the High-level findings that begin with Cleartext Password over HTTP, 2 cross sitescripting, Session Cookie Without HttpOnly Flag, and Session Cookie Without Secure Flag.Passwords should never be sent over an insecure channel without being encrypted end to end aswell establishing a distinctive hash that can be verified on both ends. This will be rectified byonly sending passwords to HTTPS targets. Having any level of password out in the open allowsfor a malicious actor to have an open door into the system. Wreaking havoc as they see fit, aswell depending on the level of access gaining administrative control and locking anyone else out.The following cross site scripting findings are also a part of the unsecure password andinformation transfer that is asking for log in credentials in an insecure location and the thenallowing user input. These are simple to correct by knowing the language and platformtechniques to filter the untrustworthy data. By allowing this the malicious actor can input code

Upload your study docs or become a

Course Hero member to access this document

Upload your study docs or become a

Course Hero member to access this document

End of preview. Want to read all 4 pages?

Upload your study docs or become a

Course Hero member to access this document

Term
Winter
Professor
N/A
Tags
HTTP cookie

Newly uploaded documents

Show More

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture