Great Circle Associates Majordomo-Workers
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: security of gen_cookie? (1.94a4)
From: Dave Barr <barr @ math . psu . edu>
Date: Tue, 23 Apr 1996 18:12:00 -0400 (EDT)
To: majordomo-workers @ greatcircle . com

	It looks like the cookie (for subscribe=..+confirm) used by
majordomo is trivially easy to compute by a third party.  I notice
there's some attempt at randomization thrown in by the $cookie_seed
variable, however this variable is never set!

	I propose a fix like this:  cookie generation would be
done by a one-way hashing function f($list,$action,$subscriber,$admin_passwd)
That would take away the ability to compute the cookie unless you knew
admin_passwd.

	That being said, we should improve the security and awareness
of passwords.  If majordomo sees the passwords haven't been changed
from the default $listname.{pass,admin} majordomo should _generate_
ones and e-mail the admin_passwd and appprove_passwd to owner-$listname
and $listname-approval respectively.  This e-mail would include an
explanation to the list owner/approver of what the password is used for
and how the list owner can change them.

--Dave



Follow-Ups:
Indexed By Date Previous: Re: wish list items
From: Brock Rozen <brozen@netvoyage.net>
Next: Re: Misspelled administrivia
From: ckk@uchicago.edu
Indexed By Thread Previous: Re: Misspelled administrivia
From: Brock Rozen <brozen@netvoyage.net>
Next: Re: security of gen_cookie? (1.94a4)
From: Sean Kamath <kamath@pogo.WV.TEK.COM>

Google
 
Search Internet Search www.greatcircle.com