maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Community (https://talk.maemo.org/forumdisplay.php?f=16)
-   -   Maemo.org security vulnerability? (https://talk.maemo.org/showthread.php?t=59830)

Jaffa 2010-08-08 10:24

Re: Maemo.org security vulnerability?
 
URL for raising this as a bug:

https://bugs.maemo.org/enter_bug.cgi....org%20Website

giecsar 2010-08-08 15:51

Re: Maemo.org security vulnerability?
 
Quote:

Originally Posted by Jaffa (Post 779375)
Then can you please do one of:
  1. Attach it to a new bug report, including details of what you did to get there; the username you've logged on with and a series of screenshots showing each expanded menu entry.
  2. Crop it and re-attach.

I'm very sorry man, it's been a few days and when HellFlyer said that Reggie saw it and it's all ok I deleted the screenshot, I figured you either didn't really care or you knew about it..

Anyway my guess (just a hypothesis) is that Midgard has a serious flaw in that it checks the validity of the username and password independently. In other words, you can, in theory, log in with a user name from any valid account and a password from any other valid account. I'm saying this because basically what happened was I logged in with Safari but I only wrote my username and the browser filled in the password for me (must have been another password because I don't usually use Safari). I was then logged in as Technical GanXta instead of giecsar, as you can see from the screenshot (that text is actually readable).

rambo 2010-08-09 14:07

Re: Maemo.org security vulnerability?
 
Quote:

Originally Posted by giecsar (Post 779616)
Anyway my guess (just a hypothesis) is that Midgard has a serious flaw in that it checks the validity of the username and password independently. In other words, you can, in theory, log in with a user name from any valid account and a password from any other valid account.

Nope, though in this case authentication is done via pam from garage db so the postgres end might have issue, but read on.

Quote:

Originally Posted by giecsar (Post 779616)
I'm saying this because basically what happened was I logged in with Safari but I only wrote my username and the browser filled in the password for me (must have been another password because I don't usually use Safari). I was then logged in as Technical GanXta instead of giecsar, as you can see from the screenshot (that text is actually readable)

More likely is that for reason you managed to somehow hit page that was cached for another user. I can't check this in detail now since I'm on a business trip but I emailed some people to look into it.


All times are GMT. The time now is 15:59.

vBulletin® Version 3.8.8