INDIAN ARMED FORCES CHIEFS ON OUR RELENTLESS AND FOCUSED PUBLISHING EFFORTS

The insightful articles, inspiring narrations and analytical perspectives presented by the Editorial Team, establish an alluring connect with the reader. My compliments and best wishes to SP Guide Publications.

— General Upendra Dwivedi, Indian Army Chief

"Over the past 60 years, the growth of SP Guide Publications has mirrored the rising stature of Indian Navy. Its well-researched and informative magazines on Defence and Aerospace sector have served to shape an educated opinion of our military personnel, policy makers and the public alike. I wish SP's Publication team continued success, fair winds and following seas in all future endeavour!"

— Admiral Dinesh Kumar Tripathi, Indian Navy Chief

Since, its inception in 1964, SP Guide Publications has consistently demonstrated commitment to high-quality journalism in the aerospace and defence sectors, earning a well-deserved reputation as Asia's largest media house in this domain. I wish SP Guide Publications continued success in its pursuit of excellence.

— Air Chief Marshal A.P. Singh, Indian Air Force Chief
       

E-commerce software vulnerable to hackers

Issue No. 20 | October 16-31, 2013

Online transactions rely on a trusted third party, or “cashier,” who bridges the gap between vendors and their customers. The use of a third party cashier, however, also complicates the payment logic and introduces a new class of vulnerabilities that can result in significant financial losses to merchants. Computer scientists found flaws in e-commerce software that allowed them to purchase stationery, candy, and toys online at below their correct cost.

A popular open-source software for e-commerce is vulnerable to being cheated, computer security researchers at the Univesity of California, Davis, have found. By exploiting vulnerabilities in the widely used osCommerce software, the researchers were able to purchase items from online stores for free or substantially less than their correct prices.

“The majority of the payment modules in osCommerce are vulnerable to logic attacks that allow you to pay less or even pay nothing at all,” said Fangqi Sun, a graduate student working with Professor Zhendong Su in the University of California (UC) Davis Department of Computer Science. A UC Davis release reports that the researchers have been attempting to notify osCommerce of the discovered vulnerabilities and to help the developers patch the software. They have also refunded the vendors for items they purchased at below cost during their research.