RE: Can you exploit this XSS?

From: Dawes, Rogan (ZA - Johannesburg) (rdawes_at_deloitte.co.za)
Date: 11/21/03

  • Next message: Nash Leon: "RE: openbsd 3.4 ps bug"
    To: 'Paul Johnston' <paul@westpoint.ltd.uk>, dd <dd@ghettohackers.net>
    Date: Fri, 21 Nov 2003 09:59:29 +0200
    
    

    >
    > P.S. Thanks to Mike Brownbill for pointing out that this is "minimal
    > risk as stealing cookies from users which aren't logged in is quite
    > simply futile" !!!

    Not so!

    I get your cookie, you log in on the next step, and the cookie does not
    change (for *MANY* applications). Now I have your cookie, and it is for an
    authenticated session.

    All it means is that you need to wait for the user to authenticate before
    ripping them off ;-)

    Simply test that they have authenticated by visiting some URL that returns
    different values based on an authenticated or unauthenticated cookie.

    Rogan

    Important Notice: This email is subject to important restrictions, qualifications and disclaimers ("the Disclaimer") that must be accessed and read by clicking here or by copying and pasting the following address into your Internet browser's address bar: http://www.Deloitte.co.za/Disc.htm. The Disclaimer is deemed to form part of the content of this email in terms of Section 11 of the Electronic Communications and Transactions Act, 25 of 2002. If you cannot access the Disclaimer, please obtain a copy thereof from us by sending an email to ClientServiceCentre@Deloitte.co.za.


  • Next message: Nash Leon: "RE: openbsd 3.4 ps bug"

    Relevant Pages

    • Re: Use owa cookie for authentication
      ... The plugin is a c# asp .net application that needs to authenticate the user ... Don't I have to decode the cadata cookie to get the ... >> There is no problem when I use NTLM in owa, but when I switch to Forms ...
      (microsoft.public.exchange.development)
    • Cookie Encryption and custom auth
      ... SSI. ... I was looking at the idea of one cookie shared across the ... the code would try and authenticate them and add the site to the list. ... roles cookie would then be created with a list of the users roles for that ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Linux/Windows Authentication?
      ... implementations I've seen used username/passwd to generate a cookie in ... the client's browser. ... > we would be looking for a transparent way to authenticate = them and to ...
      (Pen-Test)
    • Re: Single Sign on with Oracle
      ... users and then add a cookie with whatever information you need from the LDAP ... Authenticate against the Active Directoryby Using Forms ... Sam Santiago ...
      (microsoft.public.dotnet.distributed_apps)
    • Re: FormsAuthentication - Weird Behaviour
      ... a cookie is stored in there ... > problem I am having with the source code is that I cannot authenticate any> user. ... The login> component is still there. ...
      (microsoft.public.dotnet.framework.aspnet)