Re: Plone 3.3.1 __ac cookie and security

Steve McMahon <[email protected]> Thu, 28 May 2015 15:20:51 -0700
Newsgroups gmane.comp.web.zope.plone.user
Message-ID <CAOqzbghGgeMqODVSchvHiixo+9JrK07RryniuW7iC1Oqy-bWHA@mail.gmail.com>
What's described in this message isn't really a plone-specific
vulnerability. All cookie ticket systems are vulnerable to this exploit
unless sessions are encrypted.

But, let me remind everyone that possible security problems should be
addressed to security-z4DKO/[email protected], which reaches the security team. Sending
questions about suspected vulnerabilities to an open list has the potential
to hurt a lot of people.

On Thu, May 28, 2015 at 5:26 AM, eras mus <[email protected]> wrote:

> Hi,
>
> In an old Plone 3.3.1 during security audit the following was done.
>
> After logging in from login form ,the cookie __ac was captured .
> Then logged out. The logged out message got displayed  on the page.
> Now after injecting the same cookie value in the browser , When site
> is accessed it is showing as logged in.
>
> It is a security threat isn't ? Someone can capture the __ac value and log
> in.
>
> How to overcome this ?(without upgrading to new plone version)
> Please give your valuable suggestions.
>
>
> ------------------------------------------------------------------------------
> _______________________________________________
> Plone-Users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/plone-users
>

------------------------------------------------------------------------------

_______________________________________________
Plone-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-users