comp9447-team4 / soar

The main repository for comp9447-team4
3 stars 0 forks source link

Threat: Information Disclosure. Attacker leaks/wipes the data from DynamoDB #81

Closed Keung-Lee closed 3 years ago

Keung-Lee commented 3 years ago

Possible Remediation:

Keung-Lee commented 3 years ago

UPDATE

DynamoDB is NoSQL hence SQL injections is unlikely, updating this use case to focus on to the potential threat of someone who has access to the table and intentionally altering the values within the table.

Potential Remediation: