Re: myvoicestream.com vulnerability

From: Scott Dier (dieman@ringworld.org)
Date: 01/10/02


Date: Wed, 9 Jan 2002 21:06:34 -0600
From: Scott Dier <dieman@ringworld.org>
To: Trey Valenta <trey@anvils.org>



* Trey Valenta <trey@anvils.org> [020109 18:35]:
> myvoicestream.com allows VoiceStream Wireless customers to manage their
> phones and billing accounts over SSL. Access controls to sessions are

You missed the worst of it:

If you go to the 'update profile' page and view source, you can see the
currently set password. (Web authors: please stop doing this, please
leave those blank, please require reauthentication when resetting
passwords. I've found another site today apart from that that I just
notified the vendor of...)

Thus: you can hijack a session and gain a potentially re-used common
password and compromise a persons other accounts with that gained
information.

-- 
Scott Dier <dieman@ringworld.org> http://www.ringworld.org/

the desire for space travel is a metaphor for escape




Relevant Pages

  • Re: SSL
    ... Going from SSL to normal page seems to keep all the ... sessions... ... the https:// page posts to an http:// page. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Cookieless Sessions (Sessions Without Cookies) and Security
    ... If someone can sniff your connection (no SSL) - there is no difference between cookies and cookieless security-wise. ... Some suggest that SSL is the cure all for cookieless sessions. ... or at least make them as secure as sessions with cookies? ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: need quick helpp
    ... It isn't using ssl. ... Your script looks usefull but I am afraid it doesn't solve my problem. ... Knutsford Software Ltd ... > If you are using sessions and SSL - sessions arent transfered to the> other server without using server-side session token, ...
    (microsoft.public.inetserver.asp.general)
  • Re: SSL 2 and SSLV 3
    ... I use SSL with TS and web folders for remote users to ... In order for me to use SSL, ... Because we use SSL in file transfers and sessions, ...
    (microsoft.public.win2000.security)