由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
sysop版 - Re: new WWW: IP based scheme is not reliable
相关主题
lucent, huth请进can this be a bug?
Gangs of Chicago24 PORT 有问题
Re: 一个建议:WWW bug again
被踢掉的原因Suggestion about the repeat login
Re: 这个算个问题吧?求助:: 聊天视问题!
a suggestion to new interfaceFAQ--Bug (3k必须看)
WWW bug!这个BBS怎么会事儿???
建议怎么激活
相关话题的讨论汇总
话题: www话题: stamp话题: scheme话题: ip话题: let
1 (共1页)
w*h
发帖数: 7
1
mm, you still have not understood the security implication of this scheme.
Let me explain how a person B can hijack another person B's account to send
unauthorized letter under new WWW interface.
new WWW apparently uses a time stamp to maintain a login session, which is
shown in the URL: Stamp=########. The Stamp, unfortunately, is Unix time()
function return value (93####, my guess, I believe is true) when a person
login.
Let's image B logins at time X, and post a letter on this BBS at time X+y
w*h
发帖数: 7
2
mm, you still have not understood the security implication of this scheme.
Let me explain how a person B can hijack another person B's account to send
unauthorized letter under new WWW interface.
new WWW apparently uses a time stamp to maintain a login session, which is
shown in the URL: Stamp=########. The Stamp, unfortunately, is Unix time()
function return value (93####, my guess, I believe is true) when a person
login.
Let's image B logins at time X, and post a letter on this BBS at time X+y (
y is a positive number). A & B shares same proxy so they appears to have
the same IP address to the BBS server. A finds B's post and know the time X1
the letter is posted (easily got from the post itself). Now A knows if B is
online, he must login at a not so distant time before X1.
Now if A knows something of HTTP and programming, he can start trying access
http://bbs.mit.edu/cgi-bin/BBSanc?/bbslist/day&UserName=B&Stamp=X2.
This page is the top 10 hottest topics http page, it can be anything BBS WWW
page. X2 is the Unix time stamp, starts from X1. Since B won't stay so long,
probably 10 minutes later he posts his first letter, A need only try 10 * 60
times to get a positive answer to know B's login timestamp. From that time on,
A can officially fake as B and post letters in B's name!
The BBS WWW needs a more elaborated way to control Web sessions, not on IP
or any predictable ways.
1 (共1页)
相关主题
怎么激活Re: 这个算个问题吧?
Re: MIT网页的设计者是猪啊?a suggestion to new interface
帐号总是登陆不进去,请帮助~WWW bug!
又一个俱乐部的问题建议
lucent, huth请进can this be a bug?
Gangs of Chicago24 PORT 有问题
Re: 一个建议:WWW bug again
被踢掉的原因Suggestion about the repeat login
相关话题的讨论汇总
话题: www话题: stamp话题: scheme话题: ip话题: let