Topic: "Freewebs.com's weak session tracking mechanism" (page 1 of 1)

1
Author Post
quangntenemy
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
The File Manager this web host offers uses a token to track the session. However, this token is sent to the server using a get request, something like:
http://fw58.members.freewebs.com/Members/fileManager.jsp?token=xxxxx

What's even worse, when you click logout, the token isn't destroyed until it times out.
So:
- If you just click logout and go off somewhere else, your friend can still access it from the browsing history.
- If you use a tracker on your page, something like linkeXTReMe Tracking, and accidently access your page from the File Manager, the referer will get logged and a visitor to your site might click on that link to pwn your website :D
- If you put a referer tracker on the google ads on the File Manager page, maybe you'll pwn whoever clicks on that link? :D

PS: I have a website at freewebs too. Maybe it'll get pwned someday? :P
private message EMail Website
alt3rn4tiv3
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
what a great idea!
-starts on a mission to pwn quang's website ;)-
private message EMail Website
aceldama
groupmastergroupmastergroupmastergroupmaster
alternatively, if you're lazy you could always try the googledork

site:extremetracking.com inurl:login "freewebs.com" "token="
i'm guessing most of them are stale by now. good find. :drink4:

[edit]
- one could also try adding a google alert of the above-mentioned googledork and get it as soon as it happens...

- Extreme tracker does not always log the variables that you need. pity...
[/edit]

Edited by aceldama on 19.02.2007 02:46:40
private message

Topic: "Freewebs.com's weak session tracking mechanism" (page 1 of 1)

1