Re: [SC-L] [WEB SECURITY] Backdoors in custom software applications

2010-12-23 Thread Arian J. Evans
Sebastian - Looks like you got great replies! Lots of different theories and ideas here. On a day to day basis - here are the most common backdoors in webapps I've encountered over the last 15 years or so: 1) Developer Tools Backdoor hidden under obscure path 2) COTS module improperly deployed

Re: [SC-L] [WEB SECURITY] Backdoors in custom software applications

2010-12-23 Thread Steven M. Christey
On Mon, 20 Dec 2010, Arian J. Evans wrote: On a day to day basis - here are the most common backdoors in webapps I've encountered over the last 15 years or so: 1) Developer Tools Backdoor hidden under obscure path 2) COTS module improperly deployed results in backdoor 3) Custom admin module,