Repository navigation
Conversation
The library had no coverage for session fixation — determining whether an
application rotates its session identifier on authentication, and
demonstrating account takeover when it does not.
`search_skills("session fixation")` returned `csrf` at 0.27 similarity,
which is to say nothing usable.
Beyond describing the technique, the skill encodes the three things that
make the test easy to get wrong in practice:
**The frozen cookie jar.** curl rewrites a jar on every response carrying
a cookie. Without a copy taken *before* the victim authenticates, a
retained identifier is indistinguishable from a freshly issued one, and
the result proves nothing.
**The mandatory negative control.** An identifier that was never
authenticated must be refused. If it is accepted, the finding is not
fixation but the worse defect of accepting arbitrary identifiers — and
reporting the one as the other is a mis-scoring a reviewer will catch.
**Cookie-versus-URL precedence, and its trap.** Which identifier the
server honours bounds who the attack can reach, so it has to be tested.
But the obvious marker does not discriminate: servlet containers stop
URL-encoding the session id as soon as any valid session cookie is
recognised, whichever session they then act on, so both hypotheses
produce an identical page. The skill prescribes a functional marker
instead — authenticate one session, leave the other anonymous, request a
protected endpoint, and require both directions to converge.
Also covers delivery vectors per stack rather than assuming Java,
propagation through the login form's action attribute, and the CVSS
scope reasoning that UI:R lowers likelihood without capping severity
when the impacted component differs from the vulnerable one.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The library had no coverage for session fixation — determining whether an application rotates its session identifier on authentication, and demonstrating account takeover when it does not.
'search_skills("session fixation")' returned 'csrf' at 0.27 similarity, which is to say nothing usable.
Beyond describing the technique, the skill encodes the three things that make the test easy to get wrong in practice:
The frozen cookie jar. curl rewrites a jar on every response carrying a cookie. Without a copy taken before the victim authenticates, a retained identifier is indistinguishable from a freshly issued one, and the result proves nothing.
The mandatory negative control. An identifier that was never authenticated must be refused. If it is accepted, the finding is not fixation but the worse defect of accepting arbitrary identifiers — and reporting the one as the other is a mis-scoring a reviewer will catch.
Cookie-versus-URL precedence, and its trap. Which identifier the server honours bounds who the attack can reach, so it has to be tested. But the obvious marker does not discriminate: servlet containers stop URL-encoding the session id as soon as any valid session cookie is recognised, whichever session they then act on, so both hypotheses produce an identical page. The skill prescribes a functional marker instead — authenticate one session, leave the other anonymous, request a protected endpoint, and require both directions to converge.
Also covers delivery vectors per stack rather than assuming Java, propagation through the login form's action attribute, and the CVSS scope reasoning that UI:R lowers likelihood without capping severity when the impacted component differs from the vulnerable one.