Full Disclosure mailing list archives
Re: GitHub Login Cookie Failure
From: Jeffrey Walton <noloader () gmail com>
Date: Mon, 8 Apr 2013 17:43:27 -0400
On Mon, Apr 8, 2013 at 12:19 PM, Chris Roussel <lab12 () lavabit com> wrote:
I installed the "Import Cookies" & "Export Cookies" plugins in my firefox 20, then I signed in at github and exported my cookies, then I signed out, I cleaned all the cookies in my browser and I started it again, then I imported the cookies and I am login in without typing my passwords, I've tried this with my google account, but there is clear that when I signed out the info in the cookies was annulled, then it appears like I am signed while I am searching, but if I want to check my mail/drive I have to type my password.
You might also check to see if the session identifier changes between sessions. If not, GitHub may be using static session IDs, which means they could be guessable. Jeff _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- GitHub Login Cookie Failure Chris Roussel (Apr 08)
- Re: GitHub Login Cookie Failure Gregory Boddin (Apr 08)
- Re: GitHub Login Cookie Failure Jeffrey Walton (Apr 08)
- Re: GitHub Login Cookie Failure Chris Roussel (Apr 09)
- Re: GitHub Login Cookie Failure Jann Horn (Apr 08)
- Re: GitHub Login Cookie Failure Jann Horn (Apr 08)