
Уровни критичности уязвимостей
Узнать больше12.12.2024
Array ( [bSimple] => N [bAdmin] => N [arForm] => Array ( [ID] => 7 [TIMESTAMP_X] => 14.12.2022 12:26:48 [NAME] => Форма на странице appScreener [SID] => SIMPLE_FORM_7 [BUTTON] => Сохранить [C_SORT] => 300 [FIRST_SITE_ID] => [IMAGE_ID] => [USE_CAPTCHA] => N [DESCRIPTION] => [DESCRIPTION_TYPE] => text [FORM_TEMPLATE] => [USE_DEFAULT_TEMPLATE] => Y [SHOW_TEMPLATE] => [MAIL_EVENT_TYPE] => FORM_FILLING_SIMPLE_FORM_7 [SHOW_RESULT_TEMPLATE] => [PRINT_RESULT_TEMPLATE] => [EDIT_RESULT_TEMPLATE] => [FILTER_RESULT_TEMPLATE] => [TABLE_RESULT_TEMPLATE] => [USE_RESTRICTIONS] => N [RESTRICT_USER] => 0 [RESTRICT_TIME] => 0 [RESTRICT_STATUS] => [STAT_EVENT1] => form7 [STAT_EVENT2] => feedback7 [STAT_EVENT3] => [LID] => [VARNAME] => SIMPLE_FORM_7 [C_FIELDS] => 0 [QUESTIONS] => 18 [STATUSES] => 1 ) [arQuestions] => Array ( [fio] => Array ( [ID] => 38 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:02:02 [ACTIVE] => Y [TITLE] => ФИО [TITLE_TYPE] => text [SID] => fio [C_SORT] => 100 [ADDITIONAL] => N [REQUIRED] => Y [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => ФИО [RESULTS_TABLE_TITLE] => ФИО [VARNAME] => fio ) [phone] => Array ( [ID] => 39 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:02:11 [ACTIVE] => Y [TITLE] => Телефон [TITLE_TYPE] => text [SID] => phone [C_SORT] => 200 [ADDITIONAL] => N [REQUIRED] => Y [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => Телефон [RESULTS_TABLE_TITLE] => Телефон [VARNAME] => phone ) [email] => Array ( [ID] => 40 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:02:25 [ACTIVE] => Y [TITLE] => E-mail [TITLE_TYPE] => text [SID] => email [C_SORT] => 300 [ADDITIONAL] => N [REQUIRED] => Y [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => E-mail [RESULTS_TABLE_TITLE] => E-mail [VARNAME] => email ) [SIMPLE_QUESTION_351] => Array ( [ID] => 41 [FORM_ID] => 7 [TIMESTAMP_X] => 24.05.2018 10:11:02 [ACTIVE] => Y [TITLE] => Компания [TITLE_TYPE] => text [SID] => SIMPLE_QUESTION_351 [C_SORT] => 400 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => text [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => Компания [RESULTS_TABLE_TITLE] => Компания [VARNAME] => SIMPLE_QUESTION_351 ) [SIMPLE_QUESTION_433] => Array ( [ID] => 42 [FORM_ID] => 7 [TIMESTAMP_X] => 24.05.2018 10:11:02 [ACTIVE] => Y [TITLE] => Комментарий [TITLE_TYPE] => text [SID] => SIMPLE_QUESTION_433 [C_SORT] => 500 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => text [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => Комментарий [RESULTS_TABLE_TITLE] => Комментарий [VARNAME] => SIMPLE_QUESTION_433 ) [product] => Array ( [ID] => 43 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:02:48 [ACTIVE] => Y [TITLE] => Продукт [TITLE_TYPE] => text [SID] => product [C_SORT] => 600 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => Продукт [RESULTS_TABLE_TITLE] => Продукт [VARNAME] => product ) [utm_source] => Array ( [ID] => 182 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:03:11 [ACTIVE] => Y [TITLE] => utm_source [TITLE_TYPE] => text [SID] => utm_source [C_SORT] => 700 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => utm_source [RESULTS_TABLE_TITLE] => utm_source [VARNAME] => utm_source ) [utm_medium] => Array ( [ID] => 183 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:03:20 [ACTIVE] => Y [TITLE] => utm_medium [TITLE_TYPE] => text [SID] => utm_medium [C_SORT] => 800 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => utm_medium [RESULTS_TABLE_TITLE] => utm_medium [VARNAME] => utm_medium ) [utm_campaign] => Array ( [ID] => 184 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:03:29 [ACTIVE] => Y [TITLE] => utm_campaign [TITLE_TYPE] => text [SID] => utm_campaign [C_SORT] => 900 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => utm_campaign [RESULTS_TABLE_TITLE] => utm_campaign [VARNAME] => utm_campaign ) [utm_term] => Array ( [ID] => 185 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:03:39 [ACTIVE] => Y [TITLE] => utm_term [TITLE_TYPE] => text [SID] => utm_term [C_SORT] => 1000 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => utm_term [RESULTS_TABLE_TITLE] => utm_term [VARNAME] => utm_term ) [first_in] => Array ( [ID] => 186 [FORM_ID] => 7 [TIMESTAMP_X] => 18.12.2023 15:03:49 [ACTIVE] => Y [TITLE] => Первый заход [TITLE_TYPE] => text [SID] => first_in [C_SORT] => 1100 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => Y [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => Первый заход [RESULTS_TABLE_TITLE] => Первый заход [VARNAME] => first_in ) [url] => Array ( [ID] => 508 [FORM_ID] => 7 [TIMESTAMP_X] => 18.05.2022 17:04:15 [ACTIVE] => Y [TITLE] => url [TITLE_TYPE] => text [SID] => url [C_SORT] => 1200 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => url ) [clientidga] => Array ( [ID] => 509 [FORM_ID] => 7 [TIMESTAMP_X] => 18.05.2022 17:04:27 [ACTIVE] => Y [TITLE] => clientidga [TITLE_TYPE] => text [SID] => clientidga [C_SORT] => 1300 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => clientidga ) [clientidym] => Array ( [ID] => 510 [FORM_ID] => 7 [TIMESTAMP_X] => 18.05.2022 17:04:42 [ACTIVE] => Y [TITLE] => clientidym [TITLE_TYPE] => text [SID] => clientidym [C_SORT] => 1400 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => clientidym ) [gacounterid] => Array ( [ID] => 511 [FORM_ID] => 7 [TIMESTAMP_X] => 18.05.2022 17:05:01 [ACTIVE] => Y [TITLE] => gacounterid [TITLE_TYPE] => text [SID] => gacounterid [C_SORT] => 1500 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => gacounterid ) [ymcounterid] => Array ( [ID] => 512 [FORM_ID] => 7 [TIMESTAMP_X] => 18.05.2022 17:05:14 [ACTIVE] => Y [TITLE] => ymcounterid [TITLE_TYPE] => text [SID] => ymcounterid [C_SORT] => 1600 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => ymcounterid ) [marketing] => Array ( [ID] => 855 [FORM_ID] => 7 [TIMESTAMP_X] => 08.12.2022 11:44:27 [ACTIVE] => Y [TITLE] => Согласие на получение последних новостей компании, сообщений рекламного и информационного характера [TITLE_TYPE] => text [SID] => marketing [C_SORT] => 1700 [ADDITIONAL] => N [REQUIRED] => N [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => [VARNAME] => marketing ) [policy] => Array ( [ID] => 1427 [FORM_ID] => 7 [TIMESTAMP_X] => 05.06.2024 13:16:02 [ACTIVE] => Y [TITLE] => Cогласие на обработку своих данных согласно политике обработки персональных данных. [TITLE_TYPE] => text [SID] => policy [C_SORT] => 1800 [ADDITIONAL] => N [REQUIRED] => Y [IN_FILTER] => N [IN_RESULTS_TABLE] => Y [IN_EXCEL_TABLE] => Y [FIELD_TYPE] => [IMAGE_ID] => [COMMENTS] => [FILTER_TITLE] => [RESULTS_TABLE_TITLE] => Cогласие на обработку своих данных согласно политике обработки персональных данных. [VARNAME] => policy ) ) [arAnswers] => Array ( [fio] => Array ( [0] => Array ( [ID] => 38 [FIELD_ID] => 38 [QUESTION_ID] => 38 [TIMESTAMP_X] => 18.12.2023 15:02:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [phone] => Array ( [0] => Array ( [ID] => 39 [FIELD_ID] => 39 [QUESTION_ID] => 39 [TIMESTAMP_X] => 18.12.2023 15:02:11 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [email] => Array ( [0] => Array ( [ID] => 40 [FIELD_ID] => 40 [QUESTION_ID] => 40 [TIMESTAMP_X] => 18.12.2023 15:02:25 [MESSAGE] => [VALUE] => [FIELD_TYPE] => email [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [SIMPLE_QUESTION_351] => Array ( [0] => Array ( [ID] => 41 [FIELD_ID] => 41 [QUESTION_ID] => 41 [TIMESTAMP_X] => 24.05.2018 10:11:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [SIMPLE_QUESTION_433] => Array ( [0] => Array ( [ID] => 42 [FIELD_ID] => 42 [QUESTION_ID] => 42 [TIMESTAMP_X] => 24.05.2018 10:11:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => textarea [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [product] => Array ( [0] => Array ( [ID] => 43 [FIELD_ID] => 43 [QUESTION_ID] => 43 [TIMESTAMP_X] => 18.12.2023 15:02:48 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [utm_source] => Array ( [0] => Array ( [ID] => 267 [FIELD_ID] => 182 [QUESTION_ID] => 182 [TIMESTAMP_X] => 18.12.2023 15:03:11 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [utm_medium] => Array ( [0] => Array ( [ID] => 268 [FIELD_ID] => 183 [QUESTION_ID] => 183 [TIMESTAMP_X] => 18.12.2023 15:03:20 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [utm_campaign] => Array ( [0] => Array ( [ID] => 269 [FIELD_ID] => 184 [QUESTION_ID] => 184 [TIMESTAMP_X] => 18.12.2023 15:03:29 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [utm_term] => Array ( [0] => Array ( [ID] => 270 [FIELD_ID] => 185 [QUESTION_ID] => 185 [TIMESTAMP_X] => 18.12.2023 15:03:39 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [first_in] => Array ( [0] => Array ( [ID] => 271 [FIELD_ID] => 186 [QUESTION_ID] => 186 [TIMESTAMP_X] => 18.12.2023 15:03:49 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [url] => Array ( [0] => Array ( [ID] => 1020 [FIELD_ID] => 508 [QUESTION_ID] => 508 [TIMESTAMP_X] => 18.05.2022 17:04:15 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [clientidga] => Array ( [0] => Array ( [ID] => 1021 [FIELD_ID] => 509 [QUESTION_ID] => 509 [TIMESTAMP_X] => 18.05.2022 17:04:27 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [clientidym] => Array ( [0] => Array ( [ID] => 1022 [FIELD_ID] => 510 [QUESTION_ID] => 510 [TIMESTAMP_X] => 18.05.2022 17:04:42 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [gacounterid] => Array ( [0] => Array ( [ID] => 1023 [FIELD_ID] => 511 [QUESTION_ID] => 511 [TIMESTAMP_X] => 18.05.2022 17:05:01 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [ymcounterid] => Array ( [0] => Array ( [ID] => 1024 [FIELD_ID] => 512 [QUESTION_ID] => 512 [TIMESTAMP_X] => 18.05.2022 17:05:14 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [marketing] => Array ( [0] => Array ( [ID] => 1647 [FIELD_ID] => 855 [QUESTION_ID] => 855 [TIMESTAMP_X] => 08.12.2022 11:44:27 [MESSAGE] => Согласие на получение последних новостей компании, сообщений рекламного и информационного характера [VALUE] => [FIELD_TYPE] => checkbox [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [policy] => Array ( [0] => Array ( [ID] => 2234 [FIELD_ID] => 1427 [QUESTION_ID] => 1427 [TIMESTAMP_X] => 05.06.2024 13:16:02 [MESSAGE] => Да [VALUE] => Y [FIELD_TYPE] => checkbox [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) ) [arDropDown] => Array ( ) [arMultiSelect] => Array ( ) [WEB_FORM_NAME] => SIMPLE_FORM_7 [F_RIGHT] => 10 [arrVALUES] => Array ( ) [isFormErrors] => N [isFormNote] => N [isAccessFormParams] => N [isStatisticIncluded] => Y [FORM_HEADER] =>[QUESTIONS] => Array ( [fio] => Array ( [CAPTION] => ФИО [IS_HTML_CAPTION] => N [REQUIRED] => Y [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 38 [FIELD_ID] => 38 [QUESTION_ID] => 38 [TIMESTAMP_X] => 18.12.2023 15:02:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [phone] => Array ( [CAPTION] => Телефон [IS_HTML_CAPTION] => N [REQUIRED] => Y [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 39 [FIELD_ID] => 39 [QUESTION_ID] => 39 [TIMESTAMP_X] => 18.12.2023 15:02:11 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [email] => Array ( [CAPTION] => E-mail [IS_HTML_CAPTION] => N [REQUIRED] => Y [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 40 [FIELD_ID] => 40 [QUESTION_ID] => 40 [TIMESTAMP_X] => 18.12.2023 15:02:25 [MESSAGE] => [VALUE] => [FIELD_TYPE] => email [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [SIMPLE_QUESTION_351] => Array ( [CAPTION] => Компания [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 41 [FIELD_ID] => 41 [QUESTION_ID] => 41 [TIMESTAMP_X] => 24.05.2018 10:11:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [SIMPLE_QUESTION_433] => Array ( [CAPTION] => Комментарий [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 42 [FIELD_ID] => 42 [QUESTION_ID] => 42 [TIMESTAMP_X] => 24.05.2018 10:11:02 [MESSAGE] => [VALUE] => [FIELD_TYPE] => textarea [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [product] => Array ( [CAPTION] => Продукт [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 43 [FIELD_ID] => 43 [QUESTION_ID] => 43 [TIMESTAMP_X] => 18.12.2023 15:02:48 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [utm_source] => Array ( [CAPTION] => utm_source [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 267 [FIELD_ID] => 182 [QUESTION_ID] => 182 [TIMESTAMP_X] => 18.12.2023 15:03:11 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [utm_medium] => Array ( [CAPTION] => utm_medium [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 268 [FIELD_ID] => 183 [QUESTION_ID] => 183 [TIMESTAMP_X] => 18.12.2023 15:03:20 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [utm_campaign] => Array ( [CAPTION] => utm_campaign [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 269 [FIELD_ID] => 184 [QUESTION_ID] => 184 [TIMESTAMP_X] => 18.12.2023 15:03:29 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [utm_term] => Array ( [CAPTION] => utm_term [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 270 [FIELD_ID] => 185 [QUESTION_ID] => 185 [TIMESTAMP_X] => 18.12.2023 15:03:39 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [first_in] => Array ( [CAPTION] => Первый заход [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 271 [FIELD_ID] => 186 [QUESTION_ID] => 186 [TIMESTAMP_X] => 18.12.2023 15:03:49 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 0 [ACTIVE] => Y ) ) [VALUE] => ) [url] => Array ( [CAPTION] => url [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1020 [FIELD_ID] => 508 [QUESTION_ID] => 508 [TIMESTAMP_X] => 18.05.2022 17:04:15 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [clientidga] => Array ( [CAPTION] => clientidga [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1021 [FIELD_ID] => 509 [QUESTION_ID] => 509 [TIMESTAMP_X] => 18.05.2022 17:04:27 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [clientidym] => Array ( [CAPTION] => clientidym [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1022 [FIELD_ID] => 510 [QUESTION_ID] => 510 [TIMESTAMP_X] => 18.05.2022 17:04:42 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [gacounterid] => Array ( [CAPTION] => gacounterid [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1023 [FIELD_ID] => 511 [QUESTION_ID] => 511 [TIMESTAMP_X] => 18.05.2022 17:05:01 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [ymcounterid] => Array ( [CAPTION] => ymcounterid [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1024 [FIELD_ID] => 512 [QUESTION_ID] => 512 [TIMESTAMP_X] => 18.05.2022 17:05:14 [MESSAGE] => [VALUE] => [FIELD_TYPE] => text [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [marketing] => Array ( [CAPTION] => Согласие на получение последних новостей компании, сообщений рекламного и информационного характера [IS_HTML_CAPTION] => N [REQUIRED] => N [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 1647 [FIELD_ID] => 855 [QUESTION_ID] => 855 [TIMESTAMP_X] => 08.12.2022 11:44:27 [MESSAGE] => Согласие на получение последних новостей компании, сообщений рекламного и информационного характера [VALUE] => [FIELD_TYPE] => checkbox [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) [policy] => Array ( [CAPTION] => Cогласие на обработку своих данных согласно политике обработки персональных данных. [IS_HTML_CAPTION] => N [REQUIRED] => Y [IS_INPUT_CAPTION_IMAGE] => N [HTML_CODE] => [STRUCTURE] => Array ( [0] => Array ( [ID] => 2234 [FIELD_ID] => 1427 [QUESTION_ID] => 1427 [TIMESTAMP_X] => 05.06.2024 13:16:02 [MESSAGE] => Да [VALUE] => Y [FIELD_TYPE] => checkbox [FIELD_WIDTH] => 0 [FIELD_HEIGHT] => 0 [FIELD_PARAM] => [C_SORT] => 100 [ACTIVE] => Y ) ) [VALUE] => ) ) [SUBMIT_BUTTON] => [APPLY_BUTTON] => [RESET_BUTTON] => [REQUIRED_STAR] => * [CAPTCHA_IMAGE] =>
По состоянию на сентябрь 2021 г. в мире насчитывалось более 2,8 млрд активных пользователей устройств с операционной системой Android. При этом в более чем 60% приложений для девайсов на Android есть уязвимости. Проблемы свойственны не только бесплатным продуктам, но и вполне «серьезным» app, над которыми работают сильные команды специалистов. К слову, анализ безопасности APK банковских/финансовых приложений в более чем 80% случаев показывает наличие ошибок или проблем с безопасностью.
Широкое распространение Android порождает немалый спрос на услуги разработчиков под эту платформу. Иногда к работе с коммерческими проектами привлекаются специалисты с небольшим опытом. Зачастую устанавливаются сжатые сроки на разработку, из-за этого вопросам безопасности может уделяться недостаточное внимание. Чтобы избежать проблем, заказчикам и конечным пользователям Android app есть смысл перестраховаться и организовать проверку своих устройств собственными силами. Провести тестирование безопасности APK можно, например, с помощью программ для статического анализа. К этой категории относится наш продукт Solar appScreener.
Типовые уязвимости приложений для Android, которые могут эксплуатироваться злоумышленниками
В большинстве случаев разработка под Android ведется на языке Java. Некоторые модули, благодаря набору инструментов Android NDK, разрабатываются на C или С++. Соответственно, типовые уязвимости APK-приложений будут схожи с проблемами, характерными для этих языков.
Небезопасное хранение данных
Распространенная проблема, выявляемая при проверке безопасности app – небезопасное хранение пользовательских и других данных. Некоторые приложения хранят их на диске в открытом виде. В таком случае есть вероятность получения доступа к ним из любых других приложений (в том числе вредоносных), у которых есть доступ к дисковому пространству устройства. Такие уязвимости могут обнаруживаться даже в продуктах, над которыми трудятся серьезные команды. Пример – одна из версий популярного мессенджера, в которой база контактов хранилась на устройстве в открытом виде.
Небезопасная авторизация и аутентификация
Выявляемые при анализе уязвимостей APK слабые места механизмов авторизации и аутентификации дают злоумышленникам возможность обходить системы проверки паролей, прав доступа, полномочий, получать дополнительные разрешения. Это чревато кражей данных с устройств, а также другими проблемами.
Подобные уязвимости обычно возникают при использовании локальной аутентификации и уязвимых методов для ее реализации (например, удостоверение устройства), хранении паролей локально, проверке разрешений пользователей на основе информации из мобильного устройства (а не из backend-систем).
Уязвимость к SQL-инъекциям
SQL-инъекция – метод извлечения информации из базы данных. Угрозы в APK-приложениях обычно реализуются через слабые механизмы фильтрации входящих данных (например, через пользовательский ввод). Посредством SQL-инъекций злоумышленники могут читать данные из базы данных, модифицировать их, удалять или записывать – т. е. влиять на защищенность, целостность, а также доступность информации.
Неправильное использование возможностей платформы
При анализе безопасности APK часто выявляются уязвимости, связанные с неправильным использованием возможностей платформы. Они возникают из-за реализации разработчиками рекомендаций, содержащих ошибки, либо их намеренном игнорировании корректных рекомендаций.
Чаще всего встречаются уязвимости мобильных приложений Android, связанные с:
Неправильным использованием Touch ID, Face ID, а также других подобных функций, что повышает вероятность получения неавторизованного доступа к мобильному устройство Android.
Запросом чрезмерных полномочий или их неверный подбор.
Использованием открытых intents, через которые можно получить доступ к чувствительной информации.
Лишняя (неэксплуатируемая) функциональность
Добавление в приложение дополнительной функциональности (для сервисных или иных целей), наличие которой неочевидно рядовому пользователю, – довольно распространенная практика. Но это еще один из векторов атаки. Злоумышленники могут эксплуатировать такую функциональность для реализации угроз.
Проверка исходного кода Android-приложений статическим анализатором исходного кода
С проверкой исходного кода app для платформы Андроид и поиском уязвимостей неплохо справляются SAST-инструменты. Программы для статического анализа работают без запуска приложений, анализируют их исходный код и сторонние компоненты (библиотеки и проч.). Пример такого программного обеспечения – Solar appScreener.
С помощью SAST-анализатора проверяются:
Файлы манифеста. Они содержат информацию о разрешениях, запрашиваемых программным продуктом, процессах, в которых будут запускаться его компоненты, данные о связанных библиотеках.
Файлы DEX. Статический анализатор безопасности app декомпилирует их в Java. После этого он сканирует код и выявляет фрагменты/конструкции, которые могут быть небезопасными. Статический анализ позволяет выявлять различные вероятные угрозы: небезопасное хранение данных, авторизацию и аутентификацию, места, уязвимые к SQL-инъекциям, скрытую функциональность, а также другие проблемы.
Разделяемые библиотеки .so, компоненты и ресурсы приложения, а также другие типы файлов, используемые им.
Такой способ анализа уязвимостей APK может быть реализован как разработчиками на разных этапах жизненного цикла продукта, так и конечными пользователями. Например, Solar appScreener формирует результаты проверок в форме, с которой может работать даже человек, далекий от программирования (специалист по информационной безопасности, системный администратор и так далее).
ДРУГИЕ СТАТЬИ ПРОДУКТА
Еще больше о наших возможностях
Уровни критичности уязвимостей
Узнать большеSBOM (Software Bill of Materials)
Узнать большеApplication Security (AppSec): комплексная безопасность разработки приложений
Узнать большеБезопасность банковских приложений
Узнать большеТребования к безопасности ПО
Узнать большеPython проверка кода на безопасность
Узнать большеDLL проверка файлов на безопасность
Узнать большеБезопасность Python
Узнать большеPHP Проверка кода на безопасность
Узнать большеИнтеграция с JIRA
Узнать большеСамые важные новости кибербезопасности у вас в почте
Выберите темы, на которые бы вам было интересно получать новости.
Спасибо, что подписались на нашу рассылку
Для получения бесплатной консультации заполните форму ниже и отправьте заявку. Наш менеджер свяжется с вами в ближайшее время.