11.07.2015 Views

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

#1 Discovery <strong>and</strong> Exploitation• Target HTTPS-only web application– Public & private sections (registered users)– Built-in Joomla! core session management– Authentication: e-National ID card or user/pass• MD5 hashes for session ID <strong>and</strong> value– Ignore it: meaning & purpose are not required– Discovered through a blackbox pen-test but…– Source-code available: whitebox pen-testCopyright © 2011 Taddong S.L. www.taddong.com29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!