Insecure secure cookie in Tornado

看板Bugtraq作者時間16年前 (2010/08/17 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
--Signature=_Mon__16_Aug_2010_11_31_17_+0700_.NZXSYSr0i.8/Hfm Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: quoted-printable BLUE MOON SECURITY ADVISORY 2010-01 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D :Title: Insecure secure cookie in Tornado :Severity: Low :Reporter: Blue Moon Consulting :Products: Tornado v1.0 :Fixed in: Tornado v1.0.1 Description ----------- Tornado is an open source version of the scalable, non-blocking web server = and tools that power FriendFeed. A secure cookie in Tornado is stored in three parts, separated by a pipe si= gn (``|``) :: =09 <value>|<timestamp>|<hmac> where: <value> is the cookie's value encoded in Base64, which does use the digits 0 to 9. <timestamp> is ``str(int(time.time()))``. <hmac> is the keyed hash value of <value> and <timestamp> concatenated. The problem is ``get_secure_cookie`` only checks for expired timestamp and = the <hmac> does not take into account the separator character. An attacker,= therefore, can move the pipe sign to the left by 4-character blocks to cre= ate another valid cookie, whose timestamp is in the far future, and value t= runcated by 3 characters. This vulnerability is rated at low severity due to situational exploiting c= onditions. Workaround ---------- There is no workaround. Fix --- Customers are advised to upgrade to at least version 1.0.1. Disclosure ---------- Blue Moon Consulting adapts `RFPolicy v2.0 <http://www.wiretrip.net/rfp/pol= icy.html>`_ in notifying vendors. :Initial vendor contact: August 13, 2010: Notice sent to Ben Darnell. :Vendor response: August 13, 2010: Ben replied confirming the bug. :Further communication: August 13, 2010: Ben added that the attacker would have to shift by 4 dig= its due to Base64 encoding. =20 August 13, 2010: Ben added that version 1.0.1 would have a timestamp chec= k. :Public disclosure: August 16, 2010 :Exploit code: No exploit code required. Disclaimer ---------- The information provided in this advisory is provided "as is" without warra= nty of any kind. Blue Moon Consulting Co., Ltd disclaims all warranties, ei= ther express or implied, including the warranties of merchantability and fi= tness for a particular purpose. Your use of the information on the advisory= or materials linked from the advisory is at your own risk. Blue Moon Consu= lting Co., Ltd reserves the right to change or update this notice at any ti= me. --=20 Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn --Signature=_Mon__16_Aug_2010_11_31_17_+0700_.NZXSYSr0i.8/Hfm Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) iEYEARECAAYFAkxovxUACgkQbKzcTD214ZcWqQCfbNGXzcjc2AAb4VPvHvsO97dz d3QAoIcHHdKiJ4hdYZLKlMz/oTJB3mO/ =ztxV -----END PGP SIGNATURE----- --Signature=_Mon__16_Aug_2010_11_31_17_+0700_.NZXSYSr0i.8/Hfm--
文章代碼(AID): #1CQNpWfv (Bugtraq)