LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-29-2013, 04:09 PM   #1
OtagoHarbour
Member
 
Registered: Oct 2011
Posts: 332

Rep: Reputation: 3
SQL Injection and BASE (Basic Analysis And Security Engine)


I am using Debian 7.0 and am thinking of installing BASE (Basic Analysis And Security Engine) in order to handle the horrendously long Alert files generated by Snort.

One thing that makes hesitant is that I saw this article about SQL injection vulnerability with BASE. It seems that the problem may be fixed.

Does anyone know anything about this?

Thanks,
OH.
 
Old 09-29-2013, 06:38 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by OtagoHarbour View Post
It seems that the problem may be fixed. Does anyone know anything about this?
What's unclear about the message? It clearly reads "The vendor has released Basic Analysis and Security Engine version 1.2.1 to address this issue.".

*Apart from that BASE is a log reporting tool and IMNSHO any management interfaces should have secure and restricted access only.
 
Old 09-29-2013, 09:55 PM   #3
OtagoHarbour
Member
 
Registered: Oct 2011
Posts: 332

Original Poster
Rep: Reputation: 3
Quote:
Originally Posted by unSpawn View Post
*Apart from that BASE is a log reporting tool and IMNSHO any management interfaces should have secure and restricted access only.
It says it's web based and uses PHP. Does that mean it sends the data to a remote site? It does seem to use a local database. I thought the PHP could be used for local display.
 
Old 09-30-2013, 01:36 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by OtagoHarbour View Post
It says it's web based and uses PHP. Does that mean it sends the data to a remote site?
No, it means it's a web-based log analysis front end. Which average users should not be able to access.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: SQL Injection Using Havij LXer Syndicated Linux News 0 02-11-2011 10:10 AM
Vulnerability in website with sql Injection tanveer Linux - Security 7 03-28-2009 08:28 AM
SQL Injection inaki Linux - Security 6 06-04-2007 06:42 AM
LXer: Sql Injection Vulnerability LXer Syndicated Linux News 0 01-24-2006 03:16 PM
sql injection inaki Linux - Security 8 12-22-2005 10:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration