Live data from Hacker News

ServiceNow Insecure Access Control to Full Admin Takeover

x64.sh

61–70 of 81 posts

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#61
Summary from what I read:

Any user can query pretty much any table in the DB using their "GQL" wrapper around SQL. Someone thought enough to restrict the "user_password" field, so instead you query another table which gives you the user's session ID. Normally a token is user session ID + signature. But it turns out the signature wasn't really being validated, so user session ID + anything worked.

I'm normally not one to jump on mistakes, but that's remarkably bad.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#62
post #38

Earlier quoted context omitted.

My experience with this sort of enterprise software is that if you are a user, there is usually someone higher up the org chart than you that is worried such a disclosure will damage his relationship with his mate. My point being, much like Oracle, the usual timeline is that you never go public.

Yes - I worked at a place which had that experience with them. Massive outage: down for weeks, data lost, etc. We paid millions for “support” and had very little to show for it. Things escalated, and their regional VP took our senior VP out to the corporate box to discuss it over football. Monday morning, word came out to stop talking about the problem where possible. A bunch of people worked nights & weekends to get…

That story makes me incredibly angry, and quite sad, actually.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#63
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

What makes it so bad? We are likely to get it next year . I feel it cannot be worse than the aberration we are currently using but I could be wrong :-/

Many places to start, but I would say SN lacks a strong engineering culture, so everything is driven by sales and profit. That means updates come every 6 months with "features" that will never get proper support. It's shiny thing stacked on top of shiny thing and it's just a mess

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#64

Almost exactly a year from report to disclosure. I'm sure it varies a lot, but is that a normal timeline for something this severe?

ServiceNow ships major upgrades twice a year and patches every month. It means that they could genuinely not figure out how to remediate this quickly and quietly without disrupting ongoing contract negotiations. It means that even with that, they couldn't fix it for a whole year.

They negotiate multiyear contracts. they're investing into government and healthcare services.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#65

Earlier quoted context omitted.

I think all that generally applies to enterprise software like that, no? SAP is absolute garbage but it ticks various C-level agenda items (mainly the act itself of investing in ERP modernization) and so it sells regardless. Servicenow I belive makes it harder for employees to get help and thus saves labor. Enterprise software isn't for you or me, that's why we hate it.

Definitely feels like SAP is in the "nobody gets fired for buying it" category too, at least in my little slice of industry.

[deleted]

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#66
post #47

Earlier quoted context omitted.

No, there isn’t. They all have pros and cons but none overall are “better”. ServiceNow is for large orgs with independent departments/orgs who need to use it differently. There’s BMC/Remedy but it’s just as convoluted and worse. Also Clarity used to be there. There are many that are better at one one or two specific functions, sure. But none that have all the added features a large mature org would need.

Comparing remedy and ServiceNow is a bit like comparing cable television with Netflix.

[deleted]

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#67
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

I agree with other veterans? here.

ServiceNow was the better alternative all round -- as compared to Remedy and HP Service Center.

The customizations and integrations, api, cloud were decent.

The licensing was bad. The pressure to "upgrade" to latest version every year (or lose support) was insane.

Sales was aggressive.

A couple of trends probably pushed this into a hated category --

Orgs had to customize the hell out of every workflow instead of keeping it simple and following standard ITIL.

The moment you veered away from "out of the box" features and did customizations ..your yearly upgrades risked failing.

The people in Orgs who maintain and customize the tool needed to be decently skilled. Cheapest body shop vendor doesn't cut it.

ServiceNow certifications were good initially then they became expensive/unaffordable, too many, too much to keep current.

ServiceNow themselves brought into many new features like AI, chatbots, RPA etc that it all became a huge complex beast. Basic features of a ticketing tool probably became too complex to maintain?

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#68
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

Have you seen their share price though ? Boom.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#69
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

Something I've been mulling over for a while: security vulnerabilities are basically the original developers getting outsmarted, caught out being careless. Even a very skilled, careful team might ship bugs that have security implications. But low-skilled, careless teams are definitely doing this. All buggy software is also vulnerable. There is no such thing as low-quality but secure.

> security vulnerabilities are basically the original developers getting outsmarted, caught out being careless

This is absolutely not true. Security vulnerabilities can be due to a huge variety of reasons well beyond "the developer is outsmarted/careless". A great example of this was unicode related issues. Also, changing API/ABI surfaces.

And, we think of security vulnerabilities as "bugs" that cause "hacks", but sometimes vulnerabilities come in the form not in a technical hack, but attacks on users.

Sometimes, the developers know there's an issue, but the business forces them ahead anyways and takes on the risk. I've dealt with a few of those.

It's counterproductive to put it firmly on the developers, but I do agree that technical security issues and quality issues are tightly intertwined.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#70
post #35

Earlier quoted context omitted.

I recall that once upon a time, Service Manager was a client side app using the same GUI framework as Eclipse. Which made it very heavy, using tons of memory for an app that you only used now and then. I am not completely sure it was Service Manager, but quite sure. Then it was made a web app, 15+ years or so ago. Compared to that, ServiceNow is a dream to use.

The young pups here whining about ServiceNow have no idea. Service Manager, Remedy, etc were exponentially more miserable. I worked at a place that had 6 people who just twiddled Service Manager and kept the servers running etc. All ticketing systems suck. It’s the nature of the beast. People used to talk about how awesome JIRA is. Lol.

[dead]
Post reply on HN