Re: Plone 3.3.1 __ac cookie and security
Steve McMahon <[email protected]> Thu, 28 May 2015 15:20:51 -0700
| Newsgroups | gmane.comp.web.zope.plone.user |
|---|---|
| Message-ID | <CAOqzbghGgeMqODVSchvHiixo+9JrK07RryniuW7iC1Oqy-bWHA@mail.gmail.com> |
What's described in this message isn't really a plone-specific vulnerability. All cookie ticket systems are vulnerable to this exploit unless sessions are encrypted. But, let me remind everyone that possible security problems should be addressed to security-z4DKO/[email protected], which reaches the security team. Sending questions about suspected vulnerabilities to an open list has the potential to hurt a lot of people. On Thu, May 28, 2015 at 5:26 AM, eras mus <[email protected]> wrote: > Hi, > > In an old Plone 3.3.1 during security audit the following was done. > > After logging in from login form ,the cookie __ac was captured . > Then logged out. The logged out message got displayed on the page. > Now after injecting the same cookie value in the browser , When site > is accessed it is showing as logged in. > > It is a security threat isn't ? Someone can capture the __ac value and log > in. > > How to overcome this ?(without upgrading to new plone version) > Please give your valuable suggestions. > > > ------------------------------------------------------------------------------ > _______________________________________________ > Plone-Users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/plone-users > ------------------------------------------------------------------------------ _______________________________________________ Plone-Users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-users