The Mistakes Behind Most Breaches
The Most Common Serious Finding There Is
Last timeTrusting What the Caller Sent
Change one number in a request and get a stranger's invoice. It survives review because the code looks correct: the missing line is a check nobody wrote, and absence is invisible.
The shape of it
A request arrives for an invoice. It carries an identifier. The system is
careful about one thing: the caller is signed in, their session is valid,
their account is active. Satisfied, it fetches the invoice with that
identifier and returns it.
The invoice belongs to somebody else.
That is the whole flaw, and it has a dozen names in a dozen tools. The
single sentence that covers all of them: an identifier arrives from the
caller, the system acts on the record it names, and nothing established
that this caller is entitled to that record. Two different questions were
confused. Who are you was asked and answered. May you have this was never
asked at all.
Why it is everywhere
Across published assessments this class is reliably at or near the top of
the list, and the reason is not that it is subtle to understand. It is
trivial to understand. The reason is that the defect is invisible to every
process a team normally relies on.
Consider what each process sees. A reviewer reads the function: it parses
an identifier, calls the data layer, formats a response, handles errors.
Every line is correct. There is nothing to object to, because an objection
would have to be about a line that is not there. A test suite exercises
the feature as the feature was described, with one account, and it passes.
A demonstration shows it working. A static analyser looking for dangerous
functions finds none, because no function here is dangerous.
| found by reading the cod | found by a scanner, 0 or | found by testing with tw | requires knowing what sh | |
|---|---|---|---|---|
| injection into a query | 1 | 1 | 1 | 0 |
| a trusted price in the p | 1 | 1 | 0 | 0 |
| an unescaped value in a | 1 | 1 | 0 | 0 |
| a dependency with a know | 1 | 0 | 0 | 0 |
| a missing entitlement ch | 0 | 0 | 1 | 1 |
| a step that trusts an ea | 0 | 0 | 1 | 1 |
The consequence is a procedure rather than a principle. You cannot find a
missing check by looking for it. You find it by making a request that
should fail and observing that it succeeds.
The lesson stops here
3 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents