Project

General

Profile

Actions

Bug #86

closed

Feature #65: Security Audit

[Security Audit ] 21 -Insufficient Anti-Automation

Added by Kalyan Battula about 1 year ago. Updated 7 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
-
Target version:
Start date:
17/04/2024
Due date:
% Done:

0%

Estimated time:
Deployed In:
Category:

Description

21- Insufficient Anti-Automation
CWE : CWE-799
Description :
Insufficient Anti-automation is when a web site permits an attacker to automate a
process that should only be performed manually. Certain web site functionalities should
be protected against automated attacks.
Affected Path(s) :
https://earogya.satragroup.in/login *-Applicable to entire application
Impact :
Attackers could repeatedly exercise web site functionality attempting to exploit or
defraud the system. An automated robot could potentially execute thousands of requests
a minute, causing potential loss of performance or service.
Recommendation :
It is recommended to implement captcha. CAPTCHA should be perceived as a ratelimiting protection only. If it is implemented, the following considerations should be
taken into account:
No CAPTCHA information (except the image itself) should be stored on the client
side.
The client should have no "control" over the CAPTCHA content. CAPTCHA images
should be always randomly generated without possibility to perform image
preprocessing, segmentation and classification.
CAPTCHA images should not be reused.
Evidence/Proof Of Concept :
Step 1: Captcha is not implemented for the application as shown below.


Files

clipboard-202404171603-4citj.png (553 KB) clipboard-202404171603-4citj.png Kalyan Battula, 17/04/2024 04:03 PM
Actions #1

Updated by Karthik Daram 12 months ago

  • Status changed from New to Resolved
Actions #2

Updated by Karthik Daram 12 months ago

  • Assignee set to Raju Kuthadi
Actions #3

Updated by Sivakanth Kesiraju 12 months ago

  • Target version set to Sprint 1 (29th April - 3rd May)
Actions #4

Updated by Sivakanth Kesiraju 12 months ago

  • Target version changed from Sprint 1 (29th April - 3rd May) to Security Audit
Actions #5

Updated by Gautam Kumar 7 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF