View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000595 | Main CAcert Website | source code | public | 2008-08-14 02:04 | 2013-01-15 02:49 |
| Reporter | kriss | Assigned To | TheSourcerer | ||
| Priority | immediate | Severity | crash | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Platform | Main CAcert Website | ||||
| Fixed in Version | 2008 | ||||
| Summary | 0000595: Arbitrary addition to list of email addresses valid to verify a domain as being under the control of the user. | ||||
| Description | Plain and simple: https://www.cacert.org/account.php?oldid=7&newdomain=yahoo.jp&adds[]=your@email.here This will only work for the .jp domain, since spec'ing any other TLD will initialize the adds array to whatever the WHOIS information gives. Seems to be a case of register_globals + PHP being overly helpful in making an array for us + very, very bad coding standards from a security perspective. | ||||
| Additional Information | You'll find packetlogic.jp assigned to kriss@proceranetworks.com using this exploit, no certificate created / nothing to revoke. (PacketLogic is a trademark/product of Procera Networks and packetlogic.jp is owned by a local partner, so I don't foresee that anyone would have much of a legal or administrative issue with this.) | ||||
| Tags | No tags attached. | ||||
| Attached Files | |||||
| Reviewed by | |||||
| Test Instructions | |||||
|
|
I have tried it. And it works. Thanks for reporting. |
|
|
I think I fixed that bug. Please test it. Does anyone have an idea, why the .jp domains were explicitly not using whois? |
|
|
Solution has been verified and acknowledged. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2008-08-14 02:04 | kriss | New Issue | |
| 2008-08-14 02:04 | kriss | File Added: yahoo.png | |
| 2008-08-14 08:41 | homer | Note Added: 0001140 | |
| 2008-08-14 08:41 | homer | Assigned To | => TheSourcerer |
| 2008-08-14 08:41 | homer | Priority | normal => immediate |
| 2008-08-14 08:41 | homer | Severity | major => crash |
| 2008-08-14 08:41 | homer | Status | new => confirmed |
| 2008-08-14 08:41 | homer | Platform | => Main CAcert Website |
| 2008-08-14 08:56 | Sourcerer | Note Added: 0001141 | |
| 2008-08-14 08:56 | Sourcerer | Status | confirmed => solved? |
| 2008-08-14 08:56 | Sourcerer | Fixed in Version | => production |
| 2008-08-14 08:56 | Sourcerer | Resolution | open => fixed |
| 2008-08-14 11:48 | Sourcerer | Note View State: 1140: public | |
| 2008-08-14 11:49 | Sourcerer | Note Added: 0001142 | |
| 2008-08-14 11:49 | Sourcerer | Status | solved? => closed |
| 2008-08-14 12:08 | Sourcerer | View Status | private => public |
| 2013-01-15 02:49 | Werner Dworak | Fixed in Version | => 2008 |