The video of an online store, where items can be purchased on the website. However, inspecting the website shows the site running on HTTP. As per OWASP, the Sensitive Data Exposure vulnerability happens when sensitive the data is exposed while in transit or at rest. It could be done using attackers stealing keys, execute man-in-the-middle attacks, or steal clear text data off the server, while in transit, or from the userās client, e.g. browser. The most common flaw is simply not encrypting sensitive data.
This video demonstrates the data in transit and the use of HTTP for data transmission could lead to capture of the data within the network, using man in the middle attack techniques also work. Wireshark, a network monitoring tool, can show packets incoming or outgoing, or can passively monitor the network. This tool shows how the data transmitted in plain text as HTTP protocol is being used, can be used to capture the Credit Card information we had submitted over from the network.
Stay Connected
More Free Resources
About Us
Established in 2004, VISTA InfoSec is involved from Day one in providing vendor-neutral consulting services in the areas of Information Risk Compliance and Infrastructure Advisory Services. Vista Infosec most commonly provides advice on SOC 1, SOC 2, PCI DSS, HIPAA, HITRUST, GDPR, ISO 27001. Having offices in Mumbai, Singapore, USA and offering services to clients all over the world.
Phone Number: +91 9987244769
Email: info@vistainfoesc.com