Cognition Holdings responds to security concerns

Don't you like it when companies label their lack of basic OWASP security as a "malicious attack".
Some understand the fundamentals of security, others should not be let loose anywhere near an IT shop.

Shooting the messenger is a "defense" apparently. :confused:
 
That is possibly the worst response they could have given. They come off sounding completely arrogant and clueless.

It seems a lot of SA companies are too scared to admit when something is their fault. Rather make up some silly excuse about "URL manipulation" it sounds cool.
 
The case of "The Missing Link"

Cognition Holdings said:
This would have meant around 568 recipients would have [highlight]received the link[/highlight] that would have enabled them to open the fax.

I'm a bit lost with this news article, the general narrative implies that people who use this company's fax2email services "received" a url that had been crafted in some way.

Presumably the crafted url was transmitted via email? If the crafted url was sent via email, this must surely be a form of phishing.
 
I'm a bit lost with this news article, the general narrative implies that people who use this company's fax2email services "received" a url that had been crafted in some way.

Presumably the crafted url was transmitted via email? If the crafted url was sent via email, this must surely be a form of phishing.

No - simply put: fax2email exposed an object reference to an internal implementation object (in their case files and directories) without an access control check or other form of protection, hence allowing anyone having received a fax to just log into the system and do a URL traversal to view other customers data. This is poor programming and ignorance about security and I would not be surprised if the system allowed elevated administrative access and SQL injection as well to gain access to other data.

A hacker could easily sign up for an account, receive fax and then use the session to access other customers data. It is puzzling that companies like Cognition demonstrate such arrogance, rather than a simple "We messed up and thanks to the researcher we managed to patch up the issue" - security issues will always occur and working with security researchers adds tremendous value to any business.

FWIW - in our business we have close relationship to a number of security researchers and offer a bug-bounty programme to find and resolve bugs and security issues and it is something parastatals and big corporates should embrace - the value proposition and insight gained from outsiders is invaluable.
 
No - simply put: fax2email exposed an object reference to an internal implementation object (in their case files and directories) without an access control check or other form of protection, hence allowing anyone having received a fax to just log into the system and do a URL traversal to view other customers data. This is poor programming and ignorance about security and I would not be surprised if the system allowed elevated administrative access and SQL injection as well to gain access to other data.

A hacker could easily sign up for an account, receive fax and then use the session to access other customers data. It is puzzling that companies like Cognition demonstrate such arrogance, rather than a simple "We messed up and thanks to the researcher we managed to patch up the issue" - security issues will always occur and working with security researchers adds tremendous value to any business.

FWIW - in our business we have close relationship to a number of security researchers and offer a bug-bounty programme to find and resolve bugs and security issues and it is something parastatals and big corporates should embrace - the value proposition and insight gained from outsiders is invaluable.

OK understood, essentially much the same as the infamous CoJies "url hacking" thing (that you are all too familiar with).

The news article including the company's response gave (me) the impression that a manipulated url was broadcast (e.g. via email) to these 568 recipients, which seemed rather odd.

I suppose we should not be surprised if the only requirement for being granted access to other people's faxes, is simply logging in as a newly registered customer who has never received a fax.
 
Top
Sign up to the MyBroadband newsletter
X