Re: [CGP-Update] [*] CommuniGate Pro 6.2c1 is released
Nicolas Hatier <[email protected]> Wed, 15 Feb 2017 10:33:09 -0500
| Newsgroups | gmane.mail.cgatepro.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------24C2986597E1057A9BDA81AD Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable And while it's less of a security issue, you may also want to remove the = canUpdatePwd=3D1 value from login.wssp. If I'm the user of some webmail service and the administrator has set a=20 password expiration policy, I shouldn't be able to bypass that policy=20 just by removing the canUpdatePwd value from by browser POST data. *Nicolas Hatier, ing.* <[email protected]=20 <mailto:[email protected]>> Niversoft id=C3=A9es logicielles - http://www.niversoft.com On 2017-02-15 10:20, Nicolas Hatier wrote: > > Hello > > To the developers: I know this is a preliminary version. But the=20 > current implementation of the two-factor authentication for webmail=20 > has a blatant flaw, since it relies on a field being sent by the=20 > client browser. If all I have to do is to press F12 on my browser and=20 > remove the x2auth value to bypass 2fa, well, that's not very secure. I = > understand Mr Average Joe probably won't be able to do that, but=20 > that's not the point here. > > If CGP can get something directly from strings.data without relying on = > the client browser to send it, that's where I would put the x2auth=3D1 = > value. If CGP can't get something from strings.data, you may want to=20 > put an intermediate wssp step that contains a conditional server-side=20 > redirect or something like that. > > *Nicolas Hatier, ing.* <[email protected]=20 > <mailto:[email protected]>> > Niversoft id=C3=A9es logicielles - http://www.niversoft.com > > > > On 2017-02-14 15:38, Technical Support wrote: >> Major Release >> >> * SESSION: two-factor authentication framework has been implemented. >> * XIMSS: the protocol has been extended to support two-factor authenti= cation and forced password change. >> * WebUser: the interface has been extended to support two-factor authe= ntication and forced password change. >> > --------------24C2986597E1057A9BDA81AD Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Ty= pe"> </head> <body bgcolor=3D"#FFFFFF" text=3D"#000000"> <br> And while it's less of a security issue, you may also want to remove the canUpdatePwd=3D1 value from login.wssp.<br> <br> If I'm the user of some webmail service and the administrator has set a password expiration policy, I shouldn't be able to bypass that policy just by removing the canUpdatePwd value from by browser POST data.<br> <div class=3D"moz-signature"><br> <p><b>Nicolas Hatier, ing.</b> <<a style=3D"text-decoration:none= ; color:inherit" href=3D"mailto:[email protected]">nic= [email protected]</a>><br> Niversoft id=C3=A9es logicielles - <a style=3D"text-decoration:no= ne; color:inherit" href=3D"http://www.niversoft.com">http://www.niv= ersoft.com</a></p> <br> <br> </div> <div class=3D"moz-cite-prefix">On 2017-02-15 10:20, Nicolas Hatier wrote:<br> </div> <blockquote cite=3D"mid:[email protected]" type=3D"cite"> <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-= Type"> <br> Hello<br> <br> To the developers: I know this is a preliminary version. But the current implementation of the two-factor authentication for webmail has a blatant flaw, since it relies on a field being sent by the client browser. If all I have to do is to press F12 on my browser and remove the x2auth value to bypass 2fa, well, that's not very secure. I understand Mr Average Joe probably won't be able to do that, but that's not the point here.<br> <br> If CGP can get something directly from strings.data without relying on the client browser to send it, that's where I would put the x2auth=3D1 value. If CGP can't get something from strings.data,= you may want to put an intermediate wssp step that contains a conditional server-side redirect or something like that.<br> <div class=3D"moz-signature"><br> <p><b>Nicolas Hatier, ing.</b> <<a moz-do-not-send=3D"true" style=3D"text-decoration:none; color:inherit" href=3D"mailto:[email protected]">nicolas.hatier@n= iversoft.com</a>><br> Niversoft id=C3=A9es logicielles - <a moz-do-not-send=3D"true" style=3D"text-decoration:none; color:inherit" href=3D"http://www.niversoft.com">http://www.niversoft.com</a= ></p> <br> <br> </div> <div class=3D"moz-cite-prefix">On 2017-02-14 15:38, Technical Support wrote:<br> </div> <blockquote cite=3D"mid:[email protected]" type=3D"cit= e"> <pre wrap=3D"">Major Release * SESSION: two-factor authentication framework has been implemented. * XIMSS: the protocol has been extended to support two-factor authenticat= ion and forced password change. * WebUser: the interface has been extended to support two-factor authenti= cation and forced password change. </pre> </blockquote> <br> </blockquote> <br> </body> </html> --------------24C2986597E1057A9BDA81AD--