Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: ColdFusion - CFID & CFTOKEN

Re: ColdFusion - CFID & CFTOKEN

From: ron thigpen <ron_at_fuzzsonic.com>
Date: Wed, 11 May 2005 12:15:44 -0400

Jason binger wrote:
> I am currently doing some work with CF MX 6.1 and was
> wondering if anyone had some information on the
> strength of the CF cookie implementation.

More information here:
<http://www.macromedia.com/cfusion/knowledgebase/index.cfm?id=tn_18133>

Article describes a method for generating UUIDs for use as CFTOKEN
values. It is also intimated that the code for generating standard
(non-UUID) CFTOKEN values has changed in the MX release.

Seems it would be worth taking a new look at these standard CFTOKEN
values from an MX install to see if they still follow the pattern
indicated in Amit's paper.

--rt
Received on May 11 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]