Great Circle Associates Majordomo-Workers
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: security of gen_cookie? (1.94a4)
From: Brock Rozen <brozen @ netvoyage . net>
Date: Wed, 24 Apr 1996 18:30:36 -0700 (PDT)
To: Dave Barr <barr @ math . psu . edu>
Cc: majordomo-workers @ GreatCircle . COM
In-reply-to: <199604232212.SAA01016@augusta.math.psu.edu>
Reply-to: brozen @ netvoyage . net

On Tue, 23 Apr 1996, Dave Barr wrote:

> 	It looks like the cookie (for subscribe=..+confirm) used by
> majordomo is trivially easy to compute by a third party.  I notice
> there's some attempt at randomization thrown in by the $cookie_seed
> variable, however this variable is never set!
>
> 	I propose a fix like this:  cookie generation would be
> done by a one-way hashing function f($list,$action,$subscriber,$admin_passwd)
> That would take away the ability to compute the cookie unless you knew
> admin_passwd.

I would hate to have the admin_passwd be part of any hashing. How about
adding in the time (down to the second). Thus guaranteeing a unique code
each time around.

I forsee a problem though with majordomo recognizing this code as valid
when it comes back, since the time has changed. I have a few ideas for a
solution, but I'm sure there are better ones out there than actually
saving the code on the system (not SO bad if the codes are purged every 48
hours or so). Maybe using the date instead?

 -------------------------------------------------------------------------
 | Brock Rozen | brozen@netvoyage.net | http://www.netvoyage.net/~brozen |
 | Check out my Auto-Reply System -- Send me mail with subject SEND HELP |
 -------------------------------------------------------------------------




Follow-Ups:
References:
Indexed By Date Previous: Majordomo Web Interface
From: Bill Houle <Bill.Houle@SanDiegoCA.NCR.COM>
Next: Re: security of gen_cookie? (1.94a4)
From: Dave Barr <barr@math.psu.edu>
Indexed By Thread Previous: Re: security of gen_cookie? (1.94a4)
From: Sean Kamath <kamath@pogo.WV.TEK.COM>
Next: Re: security of gen_cookie? (1.94a4)
From: Dave Barr <barr@math.psu.edu>

Google
 
Search Internet Search www.greatcircle.com