Jump to content

Bug - Session Hijacking [Security Disclosure]


MoCo CoMo

Recommended Posts

Your nickname: Yok
Server: RPG 1, 3, 4
Description of the bug: Session Hijacking

The circumstances under which the bug occurred: Your session is not secured properly. Many attacker will make some programs or executable programs to steal sessions of RPG Website. I will not talk about the programs or executable programs.

 

For example, attacker succeed to send the executable programs and the victims run the programs without realizing it. The programs will upload all sessions in the browser to attacker's server.

Now, attacker knows all active sessions in the victim browser. After that, attacker will search rpg3.b-zone.ro session.

e.g : Attacker will use the victim's session and implement it into their cookies

 

ses1.jpg

 

After steal victim session, attacker just reloaded the browser. And violaaaa

Screenshot(s):

 

ses2.jpg

 

Conclusion(s):

  • If attacker succeed to send the backdoor or malware own executable programs and victims run it. ~End of the line
  • Attacker doesn't need password to login RPG UCP, they just needed session in browser. It can be configured to attacker browser and login as victim
  • Attacker can login in UCP and cannot login in game because attacker doesn't know the password. He just hijack the sessions.

I hope website developer understand about this security disclosure. All user sessions can be secured. Maybe you can use HMAC and combined expiration time.

I realized this method because i build my personal website and implements this => $_SESSION['nume']

and it can be hijaked.

 

Thank you for your time to make new generation of RPG Website. I love your design, btw. :emo:

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.