View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0000595 | Main CAcert Website | source code | public | 2008-08-14 02:04 | 2013-01-15 02:49 |
Reporter | kriss | Assigned To | TheSourcerer | ||
Priority | immediate | Severity | crash | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Platform | Main CAcert Website | ||||
Fixed in Version | 2008 | ||||
Summary | 0000595: Arbitrary addition to list of email addresses valid to verify a domain as being under the control of the user. | ||||
Description | Plain and simple: https://www.cacert.org/account.php?oldid=7&newdomain=yahoo.jp&adds[]=your@email.here This will only work for the .jp domain, since spec'ing any other TLD will initialize the adds array to whatever the WHOIS information gives. Seems to be a case of register_globals + PHP being overly helpful in making an array for us + very, very bad coding standards from a security perspective. | ||||
Additional Information | You'll find packetlogic.jp assigned to kriss@proceranetworks.com using this exploit, no certificate created / nothing to revoke. (PacketLogic is a trademark/product of Procera Networks and packetlogic.jp is owned by a local partner, so I don't foresee that anyone would have much of a legal or administrative issue with this.) | ||||
Tags | No tags attached. | ||||
Attached Files | |||||
Reviewed by | |||||
Test Instructions | |||||
|
I have tried it. And it works. Thanks for reporting. |
|
I think I fixed that bug. Please test it. Does anyone have an idea, why the .jp domains were explicitly not using whois? |
|
Solution has been verified and acknowledged. |
Date Modified | Username | Field | Change |
---|---|---|---|
2008-08-14 02:04 | kriss | New Issue | |
2008-08-14 02:04 | kriss | File Added: yahoo.png | |
2008-08-14 08:41 | homer | Note Added: 0001140 | |
2008-08-14 08:41 | homer | Assigned To | => TheSourcerer |
2008-08-14 08:41 | homer | Priority | normal => immediate |
2008-08-14 08:41 | homer | Severity | major => crash |
2008-08-14 08:41 | homer | Status | new => confirmed |
2008-08-14 08:41 | homer | Platform | => Main CAcert Website |
2008-08-14 08:56 | Sourcerer | Note Added: 0001141 | |
2008-08-14 08:56 | Sourcerer | Status | confirmed => solved? |
2008-08-14 08:56 | Sourcerer | Fixed in Version | => production |
2008-08-14 08:56 | Sourcerer | Resolution | open => fixed |
2008-08-14 11:48 | Sourcerer | Note View State: 1140: public | |
2008-08-14 11:49 | Sourcerer | Note Added: 0001142 | |
2008-08-14 11:49 | Sourcerer | Status | solved? => closed |
2008-08-14 12:08 | Sourcerer | View Status | private => public |
2013-01-15 02:49 | Werner Dworak | Fixed in Version | => 2008 |