Account Options

  1. Sign in
Google Groups Home
« Groups Home
Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Gwoo  
View profile  
 More options Jan 16 2009, 5:14 pm
From: Gwoo <gwoo.cake...@gmail.com>
Date: Fri, 16 Jan 2009 14:14:32 -0800 (PST)
Local: Fri, Jan 16 2009 5:14 pm
Subject: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
After the release of 1.2 Final, we received a lot of attention. Some
of this came in the form of a security concern. The issue could affect
sites relying on the AuthComponent for user authentication, without
the use of the SecurityComponent. Essentially, an attacker may be able
to obtain credentials as the first user of the system. If you are
interested in testing your site, you can use the SQL Inject Me plugin
for Firefox[1]

Along with several other bugs, this issue was fixed in the recently
released CakePHP 1.2.1.8004 Stable. We highly recommend that users
upgrade to this release.

A big thank you for all those who report these issues to us and allow
us to fix them.

Bake on,
CakePHP team

[1] https://addons.mozilla.org/en-US/firefox/addon/7597


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Martin Westin  
View profile  
 More options Jan 18 2009, 9:58 am
From: Martin Westin <martin.westin...@gmail.com>
Date: Sun, 18 Jan 2009 06:58:33 -0800 (PST)
Local: Sun, Jan 18 2009 9:58 am
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
Thanks for the heads-up.
Updating now...

On Jan 16, 11:14 pm, Gwoo <gwoo.cake...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
milx  
View profile  
 More options Jan 19 2009, 6:59 am
From: milx <jamierm...@googlemail.com>
Date: Mon, 19 Jan 2009 03:59:10 -0800 (PST)
Local: Mon, Jan 19 2009 6:59 am
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
Is there a link to the details of the security concern? I know it's
fixed now but I'm interested if I should always use the Security
Component and what the implication is if I don't.

Tried googling and looking in Trac but I can't seem to find out what
the problem was.

On Jan 16, 10:14 pm, Gwoo <gwoo.cake...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Pyrite  
View profile  
 More options Jan 19 2009, 8:38 am
From: Pyrite <thelette...@gmail.com>
Date: Mon, 19 Jan 2009 05:38:08 -0800 (PST)
Local: Mon, Jan 19 2009 8:38 am
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
Is there a way to test this CVE without Firefox? I do not have the
option of Firefox at work. Only IE7.

On Jan 16, 4:14 pm, Gwoo <gwoo.cake...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gwoo  
View profile  
 More options Jan 19 2009, 1:11 pm
From: Gwoo <gwoo.cake...@gmail.com>
Date: Mon, 19 Jan 2009 10:11:54 -0800 (PST)
Local: Mon, Jan 19 2009 1:11 pm
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
@mlix
changeset 7979 fixed the issue.
Security prevents CSRF and ensures that form inputs properly match the
values being submitted.

@Pyrite
im so sorry. I don't really have a way around your IE7 problem, short
of storming the castle and demanding your work installs FF.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Schreck  
View profile  
 More options Jan 21 2009, 1:31 pm
From: Schreck <Schrec...@gmail.com>
Date: Wed, 21 Jan 2009 10:31:44 -0800 (PST)
Local: Wed, Jan 21 2009 1:31 pm
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
You could probably d/l fiddler2 (http://www.fiddler2.com/fiddler2/)
and use that to do whatever injections are needed. This app also works
with any browser that supports proxies and even works remotely.

On Jan 19, 7:38 am, Pyrite <thelette...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hellfish  
View profile  
 More options Jan 24 2009, 8:28 am
From: hellfish <ruicruz...@gmail.com>
Date: Sat, 24 Jan 2009 05:28:14 -0800 (PST)
Local: Sat, Jan 24 2009 8:28 am
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
Nice to know this. I'm going to update before I write a new post
concerning what I believe is a bug in the auth component.

Brb

On Jan 21, 6:31 pm, Schreck <Schrec...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matt Curry  
View profile  
 More options Jan 24 2009, 7:18 pm
From: Matt Curry <m...@mcurry.net>
Date: Sat, 24 Jan 2009 16:18:45 -0800 (PST)
Local: Sat, Jan 24 2009 7:18 pm
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
There is a very easy way to exploit this.  I wrote about it here:
http://www.pseudocoder.com/archives/2009/01/22/cakephp-digest-6/

-Matt
http://www.pseudocoder.com


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lober  
View profile  
 More options Feb 2 2009, 3:33 am
From: lober <loxe...@hotmail.com>
Date: Mon, 2 Feb 2009 00:33:48 -0800 (PST)
Local: Mon, Feb 2 2009 3:33 am
Subject: Re: Security Notice for 1.2.0.7962, Using AuthComponent without SecurityComponent
hi gwoo i want to give you a email,but i don't know your email,so i
have a problem
about 1.20 bug

i write this in postcontroller ajax is well,but write this in
appcontroller is wrong,about ajax.
my website:www.zhuyinghao.com

 var $helpers = array('Html', 'Form', 'Javascript', 'Ajax');

On 1月17日, 上午6时14分, Gwoo <gwoo.cake...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »