Surf-Net ASP Forum Predictable Cookie ID Vulnerability
BID:3210
Info
Surf-Net ASP Forum Predictable Cookie ID Vulnerability
| Bugtraq ID: | 3210 |
| Class: | Design Error |
| CVE: |
CVE-2001-0972 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was submitted to BugTraq by Mark Lastdrager <[email protected]> on August 20th, 2001. |
| Vulnerable: |
Surf-Net ASP Forum 2.20 |
| Not Vulnerable: |
Surf-Net ASP Forum 2.30 |
Discussion
Surf-Net ASP Forum Predictable Cookie ID Vulnerability
Surf-Net ASP Forum is a free, open-source web-based message board.
Versions earlier than 2.30 of Surf-Net ASP Forum will assign a predictable sequence number for cookies saved on the machine of the user(if they choose to rely upon cookie-based authentication). Instead of attempting to randomize the ID number assigned to cookies, ASP Forum uses a sequence number directly derived from the UserID of the forum user. This makes it possible for a malicious user to locally edit the saved cookie, substituting the appropriate adminstrative cookie ID number("0888888") for the one they were assigned.
Surf-Net ASP Forum is a free, open-source web-based message board.
Versions earlier than 2.30 of Surf-Net ASP Forum will assign a predictable sequence number for cookies saved on the machine of the user(if they choose to rely upon cookie-based authentication). Instead of attempting to randomize the ID number assigned to cookies, ASP Forum uses a sequence number directly derived from the UserID of the forum user. This makes it possible for a malicious user to locally edit the saved cookie, substituting the appropriate adminstrative cookie ID number("0888888") for the one they were assigned.
Exploit / POC
Surf-Net ASP Forum Predictable Cookie ID Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Surf-Net ASP Forum Predictable Cookie ID Vulnerability
Solution:
The vendor has repaired this issue in versions 2.30 and later.
Solution:
The vendor has repaired this issue in versions 2.30 and later.
References
Surf-Net ASP Forum Predictable Cookie ID Vulnerability
References:
References:
- ASP Forum Product Page (Surf-Net)