Session & IP Spoofing

From: pire pire (pirepire69_at_romandie.com)
Date: 12/02/03

  • Next message: Micheal Thompson: "RE: Session & IP Spoofing"
    Date: Tue, 2 Dec 2003 23:01:33 +0100
    To: pen-test@securityfocus.com
    
    

    Hi,

    I've found a vulnerability in a Web App which
    gave me via an XSS the sessionID token.

    I would like to replay this token. But the
    session ID manager (on the server) seems to look
    also to IP adresses.

    So my question is: Is there a way to spoof my ip
    address in order to replay the sessionID??

    Like:
    http://www.tutu.com/toto.php?sessionid=32443243
    and some how spoof of my IP?!

    If I replay the sessionid from my machine or an
    other machine behind my NAT (same outside IP) it
    works!!

    Thanks a lot for your help

    _______________________________________________

    La messagerie gratuite des romands : 10 MO !!!
    Profitez-en ! >>> http://www.romandie.com

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Micheal Thompson: "RE: Session & IP Spoofing"

    Relevant Pages

    • Re: IP Spoofing??
      ... As a load of people from the list probably already told you, spoofing an IP ... > address in order to replay the sessionID?? ... > and some how spoof of my IP?! ...
      (Security-Basics)
    • RE: RE: Session & IP Spoofing
      ... >need is to sen I GET request with a spoofed IP! ... >You can spoof any IP. ... >gave me via an XSS the sessionID token. ... >address in order to replay the sessionID?? ...
      (Pen-Test)
    • RE: RE: Session & IP Spoofing
      ... need is to sen I GET request with a spoofed IP! ... You can spoof any IP. ... gave me via an XSS the sessionID token. ... I would like to replay this token. ...
      (Pen-Test)
    • SessionID & IP Spoofing???
      ... I've found a vulnerability in a Web App which gave me via an XSS the ... I would like to replay this token. ... Is there a way to spoof my ip address in order to ... replay the sessionID?? ...
      (comp.security.misc)
    • IP Spoofing??
      ... gave me via an XSS the sessionID token. ... I would like to replay this token. ... Is there a way to spoof my ip ... address in order to replay the sessionID?? ...
      (Security-Basics)