about cookies

From: Eduardo Caballero (sedyer@chi.spunge.org)
Date: 05/16/02


Date: Thu, 16 May 2002 08:39:26 -0500 (CDT)
From: Eduardo Caballero <sedyer@chi.spunge.org>
To: vuln-dev@securityfocus.com


-----BEGIN PGP SIGNED MESSAGE-----

  Saludos:

  This is my first post to vuln-dev list.

  Well, the cookie of audiogalaxy (www.audiogalaxy.com) on the user
system,
  reveal the username and password in plain text. This maybe a small
problem,
  but it will better even steal the session cookie; i think.

  I take advantage of this opportunity, to know your opinion regarding
this
  topic.

  Does anybody have a mean to prevent this?. Encription, ciphertext?.

  Thank you for the answers.

  ReYDeS

  P.D: Excuse my english. :)

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
Charset: noconv

iQEVAwUBPOOs6SW7thlnidfFAQFUWAgA4xtI/xRu2rQ1yi8q1He0UOfD8gCWExYr
WplE3aHHca1Ri+wsjAyi107OrG0OuKzvBXjS5LuY9z1XIxULzUSPbW80GTpaLygS
GUlEHeU8cr3DNZ0c2LgoCnehgoiH6ZocxfElkbo+TE5EQVN4e4vCfYT8/gHIAvLK
e4GiOJMhO8dsj2e05H2MWB2PY4rB9021YjdkX4GcnCN7FFtDnSF3tRwlDc/RoPa1
x/va8wLYljk3ZNFj5zL6HpXp+oOonmwGvWylHC70EzN2F+8fph7vwtLptk2oQ62S
nYUiNJO+ShofQYpBbaSCgmVzJXRmMykS+njiftWDq6+k/TRM9YY6AQ==
=omTU
-----END PGP SIGNATURE-----

. . .
 Eduardo Caballero | ReYDeS@BigFoot.com
 RareGaZz-Team Member | http://RareGaZz.com.ar
 Security Wari Projects Member | (SWP)
 ICQ: 139649191



Relevant Pages

  • Re: Audiogalaxy again (Cross Site Scripting Vuln)
    ... Audiogalaxy again ... passwords wisely and not use the same password for hotmail and mp3 sharing ... > Audiogalaxy has started storing username and passwords in cookie. ...
    (Vuln-Dev)
  • Re: Audiogalaxy again (Cross Site Scripting Vuln)
    ... Audiogalaxy again ... passwords wisely and not use the same password for hotmail and mp3 sharing ... > Audiogalaxy has started storing username and passwords in cookie. ...
    (Bugtraq)
  • [NEWS] AudioGalaxy Username and Password Saved in Cleartext
    ... that offers an mp3 sharing program. ... This product stores the username and ... password used by the application in plain text inside a cookie - this ... AudioGalaxy keeping usernames and passwords in clear text in a file on the ...
    (Securiteam)
  • Audiogalaxy again
    ... Subject: Audiogalaxy again ... has started storing username and passwords in cookie. ... a .mp3 extension and thus bo2k would not work, ...
    (Bugtraq)
  • Re: about cookies
    ... the cookie of audiogalaxy on the user ... > reveal the username and password in plain text. ... > but it will better even steal the session cookie; ...
    (Vuln-Dev)