Vulnerability Note VU#466433
Web sites may transmit authentication tokens unencrypted
Overview
Web services that rely on cookies for authentication may be vulnerable to an authentication bypass vulnerability.
Some web sites transmit authentication material (often cookies) without encrypting the entire session, even when the authentication material is initially set over an encrypted HTTP session. This behavior could allow an attacker on the network path to obtain authentication material and impersonate a legitimate user. Sites that set authentication cookies over https during login and then later transmit the cookies over HTTP are particularly vulnerable, since users are more likely to think that the security of the login page applies to the entire session.
Description
HTTP cookies are text that is sent to a client web browser from a server. Cookies are transmitted back to the server from the client's browser when the client accesses the web site. |
Impact
A remote unauthenticated attacker who can intercept traffic that is destined to an affected web site may be able to take any action on the web site that the legitimate user can. |
Solution
There are a number of options that can mitigate this type of vulnerability. Please see the Workarounds and Systems Affected sections of this document for more information, including information about specific vendors. |
Workarounds for users
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Box.net | Affected | 20 Sep 2007 | 23 Sep 2007 |
| Affected | - | 04 Nov 2008 | |
| Microsoft Corporation | Affected | - | 06 Sep 2007 |
| Yahoo, Inc. | Affected | - | 01 Sep 2007 |
| Zoho | Affected | 21 Sep 2007 | 23 Sep 2007 |
| salesforce.com | Not Affected | - | 12 Sep 2007 |
| eBay | Unknown | 06 Sep 2007 | 06 Sep 2007 |
| MySpace.com | Unknown | 05 Sep 2007 | 05 Sep 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.kb.cert.org/vuls/id/546483
- http://www.cert.org/homeusers/HomeComputerSecurity/#9
- http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html
- http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster.html
- http://www.securityfocus.com/archive/1/475658/30/0/threaded
- http://blogs.zdnet.com/Ou/?p=651
- http://blog.wired.com/monkeybites/2007/08/black-hat-repor.html
- http://tools.ietf.org/html/rfc2109
- http://wp.netscape.com/eng/ssl3/draft302.txt
- http://msdn2.microsoft.com/en-us/library/Bb250503.aspx
- http://kb.mozillazine.org/Cannot_connect_securely_because_the_site_uses_an_older_insecure_version_of_the_SSL_protocol
- http://lifehacker.com/software/email-apps/secure-webbased-email-recap-032749.php
- http://jvn.jp/cert/JVNVU%23466433/index.html
- http://gmailblog.blogspot.com/2008/07/making-security-easier.html
- http://noscript.net/faq#qa6_1
- http://www.youtube.com/watch?v=4_vhOLiZ49M&feature=channel_page
Credit
Information about this vulnerability was released by Erratasec.
This document was written by Ryan Giobbi and Dean Reges.
Other Information
- CVE IDs: Unknown
- Date Public: 07 Sep 2007
- Date First Published: 07 Sep 2007
- Date Last Updated: 13 Apr 2009
- Severity Metric: 2.25
- Document Revision: 101
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.