![]() |
|
||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
|
MIVA® SECURITY: Insecure Miva Templates #1by Ivo Truxa, 03/12/2000 Form macro attack / URL macro attack / MvCALL DoS attack Miva templates were developed long time ago and probably never redesigned with an eye to their security. I did not have time to look at them closely, but in a very quick check I found many vulnerabilities. Generally, scripts of all of us contain such vulnerabilities. It is difficult to write secure code, but it is rather easy to find some hole in almost any script. As far as nobody can see the sources, there is not too high risk. In the monent you want to publish your script, you have to crosscheck it perfectly! Many v-domains have the templates available online. And of course, anybody can access almost any Miva developer who runs Mia without a firewall on his/her machine and very probably did not bother to remove the templates. I know that I will receive angry letters telling me that I publish instructions for hackers. Well, me too, I hesitated long time before doing so, but more and more I see how carefree newcomers to Miva are. They need to be warned. If they do not see how easy it is to break in, they will never understand. In the days I write the article, Miva Co. works on fixes and I hope for an alert being sent in the very few next days, before I publish this article. Here is the first example: Form Macro Attack
|
||||||||||
|
Miva and some other terms used on this page are registerd trademarks of the Miva Corporation |