“user=admin”. Sometimes you don’t even need to log in., (Tue, Sep 30th)

One of the common infosec jokes is that sometimes, you do not need to “break” an application, but you have to log in. This is often the case for weak default passwords, which are common in IoT devices. However, an even easier method is to tell the application who you are. This does not even require a password! One of the sad recurring vulnerabilities is an HTTP cookie that contains the user's username or userid.

This article has been indexed from SANS Internet Storm Center, InfoCON: green

Read the original article: