SSCP Systems Security Certified PractitionerSystems and Application SecurityHard
A legacy application is identified as having multiple hardcoded credentials within its source code. A security audit recommends immediate remediation. Given that recompiling and redeploying the entire application is a complex and time-consuming process for a quick fix, which of the following interim mitigation strategies would be the MOST effective to reduce the immediate risk?
- AImplementing a strong Intrusion Prevention System (IPS) to detect credential misuse.
- BDisabling network access to the application from external networks.
- CImplementing a Web Application Firewall (WAF) to block access to the application.
- DChanging the hardcoded credentials on the target systems to highly complex values.
Show answer & explanationAnswer & explanation
Correct answer: D. Changing the hardcoded credentials on the target systems to highly complex values.
Changing the hardcoded credentials on the target systems to complex values immediately invalidates the easily discoverable, hardcoded credentials in the application, making them useless to an attacker. This directly addresses the vulnerability without code changes.
Why the other options are wrong
- A. An IPS might detect misuse, but it's a reactive control. Changing the credentials is a proactive measure that prevents the misuse from succeeding in the first place.
- B. Disabling external network access reduces exposure but doesn't eliminate the risk for internal attackers or if the internal network is compromised. It also impacts business functionality.
- C. A WAF might block some attacks but doesn't address the fundamental vulnerability of hardcoded credentials being known or guessable if the WAF is bypassed or application accessed internally.
Hardcoded Credential Remediation
Strategies to mitigate the risk posed by sensitive authentication information (credentials) embedded directly into application source code or configuration files, making them easily discoverable and exploitable.
- Immediate risk: discovered credentials can be used directly.
- Long-term fix: externalize secrets using secrets management.
- Interim fix: change the actual credentials on target systems.
Memory trick: Hardcoded secrets are a ticking bomb; change the locks before they come.