From fc61997665b1b89dc44c6b267fbaab23b2399ce4 Mon Sep 17 00:00:00 2001 From: Jet Hughes Date: Mon, 5 Sep 2022 12:56:18 +1200 Subject: [PATCH] vault backup: 2022-09-05 12:56:17 --- content/notes/ass01-security-audit.md | 29 +++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 content/notes/ass01-security-audit.md diff --git a/content/notes/ass01-security-audit.md b/content/notes/ass01-security-audit.md new file mode 100644 index 000000000..3d94442b8 --- /dev/null +++ b/content/notes/ass01-security-audit.md @@ -0,0 +1,29 @@ +--- +title: "ass01-security-audit" +aliases: +tags: +- assignment +- comp210 +--- + + +Jet Hughes - 9474308 + +# Summary of system +- function +- technology + +# Flaws +## Password policy +- must have at least 5 characters and one digit. + - not suffiecient + +## SQL Injection +- can log in to admin using username: " 'or 1=1;--" +- we are able to extract data which is displayed as the users username +- + +## Javascript Injection +## Path traversal +## Network-Level security +## Other \ No newline at end of file