Support #9981

[SCP ID :##5010##] : Web application pentest and Source Code review- eCustody

Added by Zahir Abd Latif about 5 years ago. Updated about 5 years ago.

Status:Closed - End of life cycleStart date:June 27, 2019
Priority:HighDue date:
Assignee:Zahir Abd Latif% Done:

100%

Category:-Spent time:-
Target version:-

Description

Hi,
Kindly attend below request:

Pentest finding

Pls review and revert on the remediation/fixes that can be done for source code review.

FW 2018- Web application pentest and Source Code review- eCustody.msg (3.31 MB) Zahir Abd Latif, June 27, 2019 09:40

FW 2018- Web application pentest and Source Code review- eCustody.msg (3.31 MB) Zahir Abd Latif, July 12, 2019 13:05

History

#1 Updated by Najmi Pasarudin about 5 years ago

  • Status changed from New - Begin Life Cycle to Development / Work In Progress

#2 Updated by Najmi Pasarudin about 5 years ago

  • % Done changed from 0 to 70
Fixes:
  1. Update affected code: MarketNews.java
  2. Remove affected code: FtpUtils.java
  3. Delete file: UPassServiceImp.java
  4. Work in progress:
    custody-main-test/ib102/corpActionPcMain.do
    custody-main-test/ib102/corpMeetingPcMain.do

#3 Updated by Najmi Pasarudin about 5 years ago

  • Status changed from Development / Work In Progress to User Acceptance Test
  • % Done changed from 70 to 90

Sent patch and pending UAT feedback.

#4 Updated by Najmi Pasarudin about 5 years ago

  • Status changed from User Acceptance Test to Pending Prod Deployment

To be deployed on 12/7/2019

#5 Updated by Zahir Abd Latif about 5 years ago

Najmi,

Others 3 file cannot be uploaded because it exceeds the maximum allowed file size (5 MB).

#6 Updated by Najmi Pasarudin about 5 years ago

Hi Zahir,

Please share custody-admin file via google drive.

#7 Updated by Najmi Pasarudin about 5 years ago

  • Assignee changed from Najmi Pasarudin to Zahir Abd Latif

Hi Zahir,

Can close this ticket.

#8 Updated by Zahir Abd Latif about 5 years ago

  • Status changed from Pending Prod Deployment to Closed - End of life cycle
  • % Done changed from 90 to 100

Syamil, Jul 15, 2019 03:02 PM:-

As spoken, ecustody pentest fixes already deploy at production on last Friday 12/7/2019.
For issue admin at sit and uat not up I will raise another ticket.

Issue closed in SCP.

Also available in: Atom PDF