Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

采用gorilla库导致API2的Cookie伪造不可用 #6

Open
t43Wiu6 opened this issue Jan 13, 2022 · 0 comments
Open

采用gorilla库导致API2的Cookie伪造不可用 #6

t43Wiu6 opened this issue Jan 13, 2022 · 0 comments

Comments

@t43Wiu6
Copy link
Contributor

t43Wiu6 commented Jan 13, 2022

稍微跟了一下,gorilla对cookie的处理中,只是用key把session id解出来
然后去找对应的文件读取用户的信息
image

1ff2092410dec2130575256ca648eb1

所以只有在知道session id的情况下才能伪造用户cookie
导致API2: Broken authentication无法正常工作
虽然/static/sessions/路由能看到id,但与预期解法不一致了

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant