How to prevent service overrides of the Naming service?
Daniel Krügler via omniORB-list <[email protected]> Wed, 28 May 2025 14:24:45 +0200
| Newsgroups | gmane.comp.corba.omniorb.user |
|---|---|
| Message-ID | <CAGNvRgCETz4RRpKwX5RAucJRWFCp-1szCQE5YuYcdNbv90+cNQ@mail.gmail.com> |
--===============5458503286350651478== Content-Type: multipart/alternative; boundary="000000000000d7ae8c06363144e4" --000000000000d7ae8c06363144e4 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, I'm aware that this is not really an OmniORB specific question, but I'm hoping that someone may still answer to that question: We are using to CORBA NamingService to register and access our services in our client/server architecture. We recently found out that it seems possible that a malicious client could simply replace our LoginService (Which is responsible for the initial connection to the service) overriding its registration in the Namingservice by a malicious LoginService implementation and thus can intercept all calls to the LoginService::login function to inspect every attempt of a user that wants to login. Is it somehow possible to prevent overriding already registered services in the NamingService or are there any other techniques to prevent this situation? Thanks, - Daniel Kr=C3=BCgler --000000000000d7ae8c06363144e4 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi,</div><div><br></div><div>I'm aware that this = is not really an OmniORB specific question, but I'm hoping that someone= may still answer to that question:</div><div><br></div><div>We are using t= o CORBA NamingService to register and access our services in our client/ser= ver architecture. We recently found out that it seems possible that a malic= ious client could simply replace our LoginService (Which is responsible for= the initial connection to the service) overriding its registration in the = Namingservice by a malicious LoginService implementation and thus can inter= cept all calls to the=C2=A0 LoginService::login function to inspect every attempt of a user that wants = to login.=C2=A0</div><div><br></div><div>Is it somehow possible to prevent = overriding already registered services in the NamingService or are there an= y other techniques to prevent this situation?</div><div><br></div><div>Than= ks,</div><div><br></div><div>- Daniel Kr=C3=BCgler</div></div> --000000000000d7ae8c06363144e4-- --===============5458503286350651478== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ omniORB-list mailing list [email protected] https://www.omniorb-support.com/mailman/listinfo/omniorb-list --===============5458503286350651478==--