Skip to content

Add session-fixation skill - #111

Open
derrouic wants to merge 1 commit into
blacklanternsecurity:mainfrom
derrouic:add-session-fixation-skill
Open

derrouic wants to merge 1 commit into
blacklanternsecurity:mainfrom
derrouic:add-session-fixation-skill

Conversation

@derrouic

Copy link
Copy Markdown

The library had no coverage for session fixation — determining whether an application rotates its session identifier on authentication, and demonstrating account takeover when it does not.
'search_skills("session fixation")' returned 'csrf' at 0.27 similarity, which is to say nothing usable.

Beyond describing the technique, the skill encodes the three things that make the test easy to get wrong in practice:

The frozen cookie jar. curl rewrites a jar on every response carrying a cookie. Without a copy taken before the victim authenticates, a retained identifier is indistinguishable from a freshly issued one, and the result proves nothing.

The mandatory negative control. An identifier that was never authenticated must be refused. If it is accepted, the finding is not fixation but the worse defect of accepting arbitrary identifiers — and reporting the one as the other is a mis-scoring a reviewer will catch.

Cookie-versus-URL precedence, and its trap. Which identifier the server honours bounds who the attack can reach, so it has to be tested. But the obvious marker does not discriminate: servlet containers stop URL-encoding the session id as soon as any valid session cookie is recognised, whichever session they then act on, so both hypotheses produce an identical page. The skill prescribes a functional marker instead — authenticate one session, leave the other anonymous, request a protected endpoint, and require both directions to converge.

Also covers delivery vectors per stack rather than assuming Java, propagation through the login form's action attribute, and the CVSS scope reasoning that UI:R lowers likelihood without capping severity when the impacted component differs from the vulnerable one.

The library had no coverage for session fixation — determining whether an
application rotates its session identifier on authentication, and
demonstrating account takeover when it does not.
`search_skills("session fixation")` returned `csrf` at 0.27 similarity,
which is to say nothing usable.

Beyond describing the technique, the skill encodes the three things that
make the test easy to get wrong in practice:

**The frozen cookie jar.** curl rewrites a jar on every response carrying
a cookie. Without a copy taken *before* the victim authenticates, a
retained identifier is indistinguishable from a freshly issued one, and
the result proves nothing.

**The mandatory negative control.** An identifier that was never
authenticated must be refused. If it is accepted, the finding is not
fixation but the worse defect of accepting arbitrary identifiers — and
reporting the one as the other is a mis-scoring a reviewer will catch.

**Cookie-versus-URL precedence, and its trap.** Which identifier the
server honours bounds who the attack can reach, so it has to be tested.
But the obvious marker does not discriminate: servlet containers stop
URL-encoding the session id as soon as any valid session cookie is
recognised, whichever session they then act on, so both hypotheses
produce an identical page. The skill prescribes a functional marker
instead — authenticate one session, leave the other anonymous, request a
protected endpoint, and require both directions to converge.

Also covers delivery vectors per stack rather than assuming Java,
propagation through the login form's action attribute, and the CVSS
scope reasoning that UI:R lowers likelihood without capping severity
when the impacted component differs from the vulnerable one.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant