Multiple Site vulnerabilities expose critical cloud computing Security Vulnerabilities

Source: Internet
Author: User

As cloud computing has become a hot technical trend, more security black holes are gradually exposed. This exposure is the network security expert Russ McRee, he demonstrated how a security defect of a cloud computing service provider puts many of its customers at risk.

Baynote, a software-as-a-service (SaaS) provider, was exposed to provide search and other network services for technology, e-commerce, and other types of websites. McRee found that an XSS (Cross-Site Scripting) error exists in Baynote's social search function. This vulnerability can be exploited to attack a large number of customers who use this function.

The vulnerability can be easily exploited by hackers, according to McRee's video (http://www.holisticinfosec.org/video/baynote/baynote.html, LSI Corporation, a host bus adapter vendor in mirpitas, California, and NetApp, a data management vendor, are two Baynote customers affected by the vulnerability.

McRee stressed that Baynote responded quickly and fixed the problem. However, his findings point out the potential critical weakness of cloud computing: the single point of failure (spof) of a vendor can affect the security of many of its customers.

He said, "Even if the SaaS vendor has only one vulnerability, it may be a Web application defect, a negligence in network security, or a mistake in physical security, all of its customers are exposed to security risks. The security strength of an enterprise depends on its weakest link. If you want other people to manage this link for you, you must consider security issues before connecting your enterprise with it ."

Prior to this, security experts have repeatedly warned enterprises not to put all eggs in one basket ." In July January this year, the downtime of Salesforce.com caused more than 0.9 million of its customers to be unable to access their key data. It also proved the security risks of relying on a provider.

Of course, this type of security problem is not only encountered by cloud computing, but enterprises cannot regard SaaS as omnipotent and must pay proper attention to the security of providers, as McRee mentioned, software as a service provider should at least provide higher security protection standards than traditional product vendors.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.