TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ServiceNow Insecure Access Control to Full Admin Takeover

171 pointsby muscawalmost 2 years ago

8 comments

chevmanalmost 2 years ago
Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow.<p>What an abomination of something seemingly so simple made into something so horrendously complex and bloated.<p>I was trying to explain to some new ServiceNow AE why we wouldn&#x27;t be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users.<p>It behaves like it is constantly broken.<p>People talk shit about it all day, every day.<p>Maybe one day, some time a long time ago they had a good product, and that&#x27;s how it got embedded all over the place, but now, what a pile of junk!
评论 #36639676 未加载
评论 #36639076 未加载
评论 #36643524 未加载
评论 #36639509 未加载
评论 #36639761 未加载
评论 #36641127 未加载
评论 #36639204 未加载
评论 #36641856 未加载
评论 #36639012 未加载
评论 #36640543 未加载
评论 #36640868 未加载
评论 #36640806 未加载
评论 #36639048 未加载
评论 #36639448 未加载
评论 #36639182 未加载
评论 #36640199 未加载
评论 #36639732 未加载
评论 #36653604 未加载
评论 #36641042 未加载
评论 #36642038 未加载
rzimmermanalmost 2 years ago
Summary from what I read:<p>Any user can query pretty much any table in the DB using their &quot;GQL&quot; wrapper around SQL. Someone thought enough to restrict the &quot;user_password&quot; field, so instead you query another table which gives you the user&#x27;s session ID. Normally a token is user session ID + signature. But it turns out the signature wasn&#x27;t really being validated, so user session ID + anything worked.<p>I&#x27;m normally not one to jump on mistakes, but that&#x27;s remarkably bad.
frakt0x90almost 2 years ago
Almost exactly a year from report to disclosure. I&#x27;m sure it varies a lot, but is that a normal timeline for something this severe?
评论 #36638966 未加载
评论 #36640198 未加载
评论 #36638882 未加载
评论 #36639486 未加载
评论 #36641339 未加载
pmlnralmost 2 years ago
Ah, ServiceNow. We had to hold a formal code review on the steaming pile of turd they delivered because it was so incredibly bad even testing it would have been a security risk. That&#x27;s the quality you get from them.
mschuster91almost 2 years ago
And yet, it&#x27;s leagues better than HP Service Manager or, heaven forbid, that ticket system someone created in Lotus Notes...<p>Ticket systems are always a giant pain.
dvorak_typistalmost 2 years ago
InSecurityNow? Fuck&#x27;m with prejudice. Keep digging.<p>RCE as admin has been a problem for over a decade. _Globally_ sessions do not expire... This is just the tip of the shit architecture iceberg.
pm2222almost 2 years ago
My vote goes to snow it’s much better than servicecenter and remedy. I’m a user only not admin or dev.
评论 #36641282 未加载
评论 #36640777 未加载
miguelazoalmost 2 years ago
Does anyone else get a security warning about a background download when visiting this page?