middleware corba vulnerabilities:do they exist?

From: william fitzgerald (williamfat_private)
Date: Thu Aug 07 2003 - 07:25:42 PDT

  • Next message: Jason Coombs: "RE: Anyone looked at the canary stack protection in Win2k3?"

    Hi all, 
    
    I am not sure what forum I should have posted this on so if you know let me
    know for next time. 
    
    I have been researching corba and corba security as a hobbie recently. Corba
    security seems to be solid from the omg corba security services 1.8 manual (only
    got through half of that spec so far). 
    
    does corba have any security flaws that could be improved or are worth a research
    investigation? 
    
    there must be ways to upset corba security services either intentionaly or unintentionaly.
    it seems to be heavily governed on policies. is the a vulnerability here? 
    
    what about other middleware technologies such as ejb? are there security issues
    here? 
    
    or do security issues arise when using both ejb and corba together? 
    
    any information relating to corba security is welcomed. the omg specification
    wont highlight any existing security exploits for obvious reasons. 
    
    I done a google seearch for "corba security vulnerabilites" but no security
    problems were returned. 
    
    Kind regards, 
    Will.
    
    Mr. William Fitzgerald (MSc,BSc)
    Ericsson Systems Expertise Ltd.,
    Radio House, Beech Hill,
    Dublin 4.
    ph: 087 95 27 083
    http://www.may.ie
    



    This archive was generated by hypermail 2b30 : Thu Aug 07 2003 - 16:39:42 PDT