Scenario:
I work for a company that purchased a bespoke web based database application a couple years ago. We hold highly sensitive personalised information, so security is important.
The company that created the system for us is a bit of a joke. But as it was all done before I came along, nothing i can do about it. (we are in the process of looking for someone else to do a rewrite and support the dang thing)
Anywho’s, poking about this morning..(not my job to do so, but occasionally do so for the entertainment value…) and look-see what I found in the Web.config file (inetpub/wwwroot/appfolder):
Keep in mind, I have replaced the values with asteriks, in the file, they are there in plain view.
Now..if something would have happened in the previous 2 years and someone was going down for it..who has responsibility??
Is it our fault for not having web dev’s to look after this, or is it their fault for developing it like this in the first place??
Just curious…
Now as I’m the one who found it, i get the pleasure of asking them to get their heads out of their @sses and explain why this is there as well as ask (nicely) that it be changed immediatly.