Security Hole?

T

Tony

I think I found a security hole in PDS that's simple to exploit. I'm
hoping someone knows how I can close this up because it's a snap to
exploit.

Build a web page or start a VB project that makes an XML call for the
<Request><GetLoginInformation/></Request> command. What gets returned
is the db login for the MSPServerUser. Note, this is not restricted to
Admins only: Project Managers, Portfolio Managers and Resource Managers
can all make this call (Team Members, Team Leaders and Executives get a
50 status returned). With this login, they have unrestricted access to
the database.

The database login is returned in human readable format to people who
are not admins--this poses a significant security risk, especially
because it's so easy to exploit.

Is there a way to close this hole?

Best,
-Tony
 
M

Mike Glen

Hi Tony,

Try posting on the server newsgroup as this one is closing down. Please see
FAQ Item: 24. Project
Newsgroups. FAQs, companion products and other useful Project information
can be seen at this web address: http://project.mvps.org/faqs.htm

Mike Glen
Project MVP
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top