X-Git-Url: https://git.martlubbers.net/?a=blobdiff_plain;f=report%2Fv4_access.tex;h=897529907975ecc88aa8a2fca8dda140602ddf11;hb=3c8879cf6599fdcea20ac18910260e929d65bec4;hp=45b75158d27f2642c25eabfb83261d33f0190558;hpb=67f014d95fdc06c3170f805afae6a48fa101bb3f;p=ssproject1617.git diff --git a/report/v4_access.tex b/report/v4_access.tex index 45b7515..8975299 100644 --- a/report/v4_access.tex +++ b/report/v4_access.tex @@ -94,13 +94,15 @@ Fail, because the role and distinct user systems are stubs. \end{result} \item -\pass{} +\fail{} Verify that all user and data attributes and policy information used by access controls cannot be manipulated by end users unless specifically authorized. \begin{result} -This item is the main remaining security concern. I haven't found any obvious fail in the login system, but given the architecture and security status of the whole \CMS{}, I'm not very sure of it. +This item is the main remaining security concern, as the login form allows SQL +injections that are capable to alter any information stored in the database. +This is described in more detail in item V2.6 on page~\pageref{auth:6}. \end{result} \notapplicable{