OTRSSession security risk ?

Moderator: crythias

Locked
Arr
Znuny newbie
Posts: 1
Joined: 30 Mar 2011, 11:03
Znuny Version: 3.0.5

OTRSSession security risk ?

Post by Arr »

Hello,

when i set manually a known session id into the url field of my browser, i can furtherway substitute and act as the user who owns the session generally without any login+password procedure

is it a little too big security risk ?

asks
Arndt
Alexander Halle
Znuny expert
Posts: 296
Joined: 04 Jul 2010, 17:49
Znuny Version: 3.1.x
Real Name: Alexander Halle
Company: radprax MVZ GmbH
Location: Wuppertal
Contact:

moved topic

Post by Alexander Halle »

(moved from the developer forum to the appropriate forum)
Alexander Halle System: OTRS 3.1.x, Ubuntu 10.04.x LTS, MySQL 5.1.x, Apache 2.2.x
OTRS Community Links: User Meetings, Projects
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: OTRSSession security risk ?

Post by jojo »

it seems that you switched of the IP Check for the session handling...
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
Locked