June 10, 2009

StrongWebMail Weak On The Inside

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

Last week I mentioned StrongWebMail - a company that claimed they offer the strongest Web mail on the planet. That claim was proven false when a team of researchers bypassed security using an obvious inroad.

You might recall that StrongWebMail uses a callback technique during the login process. Basically you get a phone call when you try to login. You have to enter the PIN number given to you during the call in order to complete the logon process. Sounds pretty good, right? But what about after you login?

While the developers at StrongWebMail were busy protecting the gates to the kingdom they apparently overlooked the need to both lock the doors inside to prevent people from roaming around and forgot to guard the users themselves in case they decided to roam around.

According to IDG, the researchers created an email account of their own and once logged in they found ample room for manipulation - to the point of being able to gain access to StrongWebMail CEO's calendar. Internal security was very lax. Game over.

End of Article



Windows IT Pro Community
Blogs






Search Security Matters
 
Security Matters
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Security Matters
Wordpress 2.8.4 Fixes A Big Security Hole
Make a Comment
Microsoft Releases 5 Critical Patches
Make a Comment
How To Help Secure HTTP Data Without SSL

Last Comment
The article has very less information. Need some elaboration....
(1 Comments)
Sometimes The Cookie Doesn't Crumble
Make a Comment
SecureTweets for Twitter
Make a Comment

More blogs about technology,
software, and Windows.

SQL Server Magazine Office & SharePoint Pro DevProConnections asp.netPRO ITTV
IT Library Technology Resource Directory Connected Home Windows SuperSite
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc.     Terms of Use | Privacy Statement