Full Disclosure mailing list archives

Re: GitHub Login Cookie Failure


From: Jeffrey Walton <noloader () gmail com>
Date: Mon, 8 Apr 2013 17:43:27 -0400

On Mon, Apr 8, 2013 at 12:19 PM, Chris Roussel <lab12 () lavabit com> wrote:

I installed the "Import Cookies" & "Export Cookies" plugins in my
firefox 20, then I signed in at github and exported my cookies, then I
signed out, I cleaned all the cookies in my browser and I started it
again, then I imported the cookies and I am login in without typing my
passwords, I've tried this with my google account, but there is clear
that when I signed out the info in the cookies was annulled, then it
appears like I am signed while I am searching, but if I want to check my
mail/drive I have to type my password.
You might also check to see if the session identifier changes between
sessions. If not, GitHub may be using static session IDs, which means
they could be guessable.

Jeff

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: