Re: [CGP-Update] [*] CommuniGate Pro 6.2c1 is released

Nicolas Hatier <[email protected]> Wed, 15 Feb 2017 10:33:09 -0500
Newsgroups gmane.mail.cgatepro.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------24C2986597E1057A9BDA81AD
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable


And while it's less of a security issue, you may also want to remove the =

canUpdatePwd=3D1 value from login.wssp.

If I'm the user of some webmail service and the administrator has set a=20
password expiration policy, I shouldn't be able to bypass that policy=20
just by removing the canUpdatePwd value from by browser POST data.

*Nicolas Hatier, ing.* <[email protected]=20
<mailto:[email protected]>>
Niversoft id=C3=A9es logicielles - http://www.niversoft.com



On 2017-02-15 10:20, Nicolas Hatier wrote:
>
> Hello
>
> To the developers: I know this is a preliminary version. But the=20
> current implementation of the two-factor authentication for webmail=20
> has a blatant flaw, since it relies on a field being sent by the=20
> client browser. If all I have to do is to press F12 on my browser and=20
> remove the x2auth value to bypass 2fa, well, that's not very secure. I =

> understand Mr Average Joe probably won't be able to do that, but=20
> that's not the point here.
>
> If CGP can get something directly from strings.data without relying on =

> the client browser to send it, that's where I would put the x2auth=3D1 =

> value. If CGP can't get something from strings.data, you may want to=20
> put an intermediate wssp step that contains a conditional server-side=20
> redirect or something like that.
>
> *Nicolas Hatier, ing.* <[email protected]=20
> <mailto:[email protected]>>
> Niversoft id=C3=A9es logicielles - http://www.niversoft.com
>
>
>
> On 2017-02-14 15:38, Technical Support wrote:
>> Major Release
>>
>> * SESSION: two-factor authentication framework has been implemented.
>> * XIMSS: the protocol has been extended to support two-factor authenti=
cation and forced password change.
>> * WebUser: the interface has been extended to support two-factor authe=
ntication and forced password change.
>>
>


--------------24C2986597E1057A9BDA81AD
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Ty=
pe">
  </head>
  <body bgcolor=3D"#FFFFFF" text=3D"#000000">
    <br>
    And while it's less of a security issue, you may also want to remove
    the canUpdatePwd=3D1 value from login.wssp.<br>
    <br>
    If I'm the user of some webmail service and the administrator has
    set a password expiration policy, I shouldn't be able to bypass that
    policy just by removing the canUpdatePwd value from by browser POST
    data.<br>
    <div class=3D"moz-signature"><br>
      <p><b>Nicolas Hatier, ing.</b> &lt;<a style=3D"text-decoration:none=
;
          color:inherit" href=3D"mailto:[email protected]">nic=
[email protected]</a>&gt;<br>
        Niversoft id=C3=A9es logicielles - <a style=3D"text-decoration:no=
ne;
          color:inherit" href=3D"http://www.niversoft.com">http://www.niv=
ersoft.com</a></p>
      <br>
      <br>
    </div>
    <div class=3D"moz-cite-prefix">On 2017-02-15 10:20, Nicolas Hatier
      wrote:<br>
    </div>
    <blockquote
      cite=3D"mid:[email protected]"
      type=3D"cite">
      <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-=
Type">
      <br>
      Hello<br>
      <br>
      To the developers: I know this is a preliminary version. But the
      current implementation of the two-factor authentication for
      webmail has a blatant flaw, since it relies on a field being sent
      by the client browser. If all I have to do is to press F12 on my
      browser and remove the x2auth value to bypass 2fa, well, that's
      not very secure. I understand Mr Average Joe probably won't be
      able to do that, but that's not the point here.<br>
      <br>
      If CGP can get something directly from strings.data without
      relying on the client browser to send it, that's where I would put
      the x2auth=3D1 value. If CGP can't get something from strings.data,=

      you may want to put an intermediate wssp step that contains a
      conditional server-side redirect or something like that.<br>
      <div class=3D"moz-signature"><br>
        <p><b>Nicolas Hatier, ing.</b> &lt;<a moz-do-not-send=3D"true"
            style=3D"text-decoration:none; color:inherit"
            href=3D"mailto:[email protected]">nicolas.hatier@n=
iversoft.com</a>&gt;<br>
          Niversoft id=C3=A9es logicielles - <a moz-do-not-send=3D"true"
            style=3D"text-decoration:none; color:inherit"
            href=3D"http://www.niversoft.com">http://www.niversoft.com</a=
></p>
        <br>
        <br>
      </div>
      <div class=3D"moz-cite-prefix">On 2017-02-14 15:38, Technical
        Support wrote:<br>
      </div>
      <blockquote cite=3D"mid:[email protected]" type=3D"cit=
e">
        <pre wrap=3D"">Major Release

* SESSION: two-factor authentication framework has been implemented.
* XIMSS: the protocol has been extended to support two-factor authenticat=
ion and forced password change.
* WebUser: the interface has been extended to support two-factor authenti=
cation and forced password change.

</pre>
      </blockquote>
      <br>
    </blockquote>
    <br>
  </body>
</html>

--------------24C2986597E1057A9BDA81AD--