INDIAN ARMED FORCES CHIEFS ON
OUR RELENTLESS AND FOCUSED PUBLISHING EFFORTS

 
SP Guide Publications puts forth a well compiled articulation of issues, pursuits and accomplishments of the Indian Army, over the years

— General Manoj Pande, Indian Army Chief

 
 
I am confident that SP Guide Publications would continue to inform, inspire and influence.

— Admiral R. Hari Kumar, Indian Navy Chief

My compliments to SP Guide Publications for informative and credible reportage on contemporary aerospace issues over the past six decades.

— Air Chief Marshal V.R. Chaudhari, Indian Air Force Chief
       

Bugs get through superannuation fund

Issue No. 4 | February 16-29, 2012

Well-known Australian information security professional Patrick Webster has been visited by NSW Police officers following his disclosure of an embarrassing Web application security bug to his superannuation fund.

Webster had noticed his pension fund, First State Superannuation allowed logged in members to access online statements via “direct object reference,” a security lapse so boneheaded it is included in OWASP’s infamous top ten list of web application security bugs.

For those unfamiliar with direct object reference, it means documents are served up by way of a direct ID in a URL. The problem is that by changing the document ID in the browser’s URL bar, another document will be accessed and served to the user.