Feeds

THOUSANDS of Ruby on Rails sites leave logins lying around

Unexpired session cookies can be stolen, re-used

Remote control for virtualized desktops

A security researcher has warned that a Ruby on Rails vulnerability first outlined in September is continuing to linger on the Web, courtesy of admins that don't realise a vulnerability exists in its default CookieStore session storage mechanism.

The weakness affects some big names, with the research turning up names like Warner Bros, Kickstarter, and the popular Tweet-aggregator tool Paper.li.

As US researcher G.S. McNamara detailed in September, the problem is that CookieStore retains valid session cookies at the client-side forever. This is referred to as an “insufficient session expiration” weakness.

That means if a malicious attacker were to steal the cookie from any authenticated request (via, for example, an XSS attack that gives the attacker access to a user's cookie store, but there's a host of other ways to get a copy of the cookie), they could use it to impersonate the victim and log into the Ruby Web app.

It also poses a risk for people using public terminals, or office computers that could be accessed by workmates.

As ThreatPost explained at the time, “the app issues a new cookie in the browser to overwrite the one that was created when the user was authenticated. Rails tells the browser to recognise that new cookie … but the old one still works, it hasn’t been invalidated and can’t be, by default”.

McNamara's recommendation is that admins should abandon CookieStore in favour of other mechanisms such as ActiveRecordStore – but his latest work finds that this isn't happening.

Instead, he's found 1,897 sites - including the names mentioned above - that are still using the weak CookieStore mechanism.

“This is not an exhaustive list,” he writes, “and there is future work to be done in detecting remotely the use of Rails’ CookieStore with encrypted values”. Django’s cookie storage is also bad at expiring cookies, and McNamara says he will continue the research to identify sites that haven't altered their cookie storage. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.