TOLOGIX - ISLG Maintenance

Project dealing with all ongoing maintenance of the current ISLG application (www.investorstatelawguide.com and dev.investorstatelawguide.com).

Security - Development


Comments & Events

Morgan Maguire, CEO
Hi Anil Vaghela Anil and Harsh Parikh, Tech Lead at DevIT Harsh ,

Are we still working through resolving these to-do's?

Thanks,

Morgan 
Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan ,

We are working on Remote OS Command Injection and Format String error task simultaneously. Both task need R & D to resolve the error. 

We will keep you updated.
Morgan Maguire, CEO
OK. Sounds good Harsh Parikh, Tech Lead at DevIT Harsh . Thanks for the update.

Morgan 
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh and Harsh Parikh, Tech Lead at DevIT Harsh ,
 
I know that resources are 100% dedicated to the ISLG Rebuild and HTML Conversion projects. However, I think we should still dedicate some time each week to continue working through the outstanding security issues flagged in this to-do list. Also, I'm sure issues resolved in the current application could help inform the team to prevent the same issue from coming up again in the new ISLG and ILG. What are your thoughts on how to allocated resources appropriately?

Thanks,

Morgan 
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh and Harsh Parikh, Tech Lead at DevIT Harsh ,

An additional note on the above. I discussed this with Ryan Knuth, Customer Support Manager at Industrial Ryan , and assuming we can figure out a sensible way to allocate resources to the project, Ryan Knuth, Customer Support Manager at Industrial Ryan will run an additional scan to ensure we're dealing current issues, and update the appropriate to-do's.
 
Thanks,

Morgan 
Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan and Ryan Knuth, Customer Support Manager at Industrial Ryan ,

We have already analyzed some of the security development tasks and found that some tasks need fundamentally change of current ISLG application  structure

(For an ex. SQL Injection - 1 and SQL Injection - 2 both tasks need to change the Querystring  structure which we passed as parameter in application's URL.)

Please take a note that we have developed new ISLG architecture with prevent all security aspects. Hence, New ISLG application will never found security related issues.

But, We will definitely look into the current Security Development tasks and try to resolve as much as possible.

Could you please tell us that Security Development tasks are on High Priority or not ?
Morgan Maguire, CEO
Hi Harsh Parikh, Tech Lead at DevIT Harsh ,

That makes sense. We can avoid the tasks that require fundamentally changing the application structure, as long as we're ensuring the new application will not have the same issues.

How about this: Ryan Knuth, Customer Support Manager at Industrial Ryan will run another security scan. We'll see what issues are outstanding, and then we'll tackle those issues that are a high priority and require less resources.

Let us know if that approach makes sense.

Thanks,

Morgan 
Morgan Maguire, CEO
Hi Ryan Knuth, Customer Support Manager at Industrial Ryan ,

We can discuss this during our call in 20 minutes, but just confirming that you're planning to perform an updated security scan to identify any high priority problems on the current ISLG application.

Thanks,

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

currently you are listed security issue in current ISLG, I have study those points and find out reason behind it, Major factor of those points are URL, In current ISLG  parameter/data passing in URL and it will cause security issue like injection for security aspects so I am planning to omit all parameter from URL so in new ISLG site we are developing such way and all action/operation should be partial rendering with AJAX.

In short, Add/Edit will be render in browser for each functionality but not change URL. so when u suppose to refresh it will display original page in browser.

Please find attached video of screen capture for better understanding.


 
Morgan Maguire, CEO
OK. Sounds good Jitesh Dhuravala, DevIT Jitesh . Sounds like a good plan to me on the new ISLG application. However, will this create any problems with users (particularly on the front-end) if they bookmarking URLs. For example, if the same URL applies to several pages, will that prevent them from bookmarking a specific locations on the website? Also, will this create any issues in trying to report and troubleshoot problems we come across with UAT?

Regardless, Ryan Knuth, Customer Support Manager at Industrial Ryan , have you run the security scan on the current ISLG application?
 
Thanks,

Morgan 
Ryan Knuth, Customer Support Manager at Industrial
Hi Morgan Maguire, CEO Morgan and Jitesh Dhuravala, DevIT Jitesh  

The scan completed yesterday and I'm currently reviewing the results. I'll post the report later today.

Thanks!

Ryan 
Morgan Maguire, CEO
Perfect. Thanks Ryan Knuth, Customer Support Manager at Industrial Ryan .

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

It will not create any problem in any functionality, as specially you are talking about bookmark so it will manage by business logic so all functionality/cases have in our hand so we will do business logic or impliment functinality in such way and we do achieve all functionality. so don't worry about it.

Thanks,
Jitesh
Morgan Maguire, CEO
OK. Sounds good Jitesh Dhuravala, DevIT Jitesh . Assuming Ryan Knuth, Customer Support Manager at Industrial Ryan doesn't have any further input, I'm fine with the proposed solution.

Thanks,

Morgan