X-Git-Url: https://git.martlubbers.net/?a=blobdiff_plain;f=report%2Fv4_access.tex;h=897529907975ecc88aa8a2fca8dda140602ddf11;hb=9c1499262174ffd37af6f6e94de0da1901e2dc66;hp=45b75158d27f2642c25eabfb83261d33f0190558;hpb=db9adf4baa5dabb6cb7df7a57fc0aa22881e785e;p=ssproject1617.git diff --git a/report/v4_access.tex b/report/v4_access.tex index 45b7515..8975299 100644 --- a/report/v4_access.tex +++ b/report/v4_access.tex @@ -94,13 +94,15 @@ Fail, because the role and distinct user systems are stubs. \end{result} \item -\pass{} +\fail{} Verify that all user and data attributes and policy information used by access controls cannot be manipulated by end users unless specifically authorized. \begin{result} -This item is the main remaining security concern. I haven't found any obvious fail in the login system, but given the architecture and security status of the whole \CMS{}, I'm not very sure of it. +This item is the main remaining security concern, as the login form allows SQL +injections that are capable to alter any information stored in the database. +This is described in more detail in item V2.6 on page~\pageref{auth:6}. \end{result} \notapplicable{