Skip to content

Security warning: Replay attack possible #4

@clecap

Description

@clecap

If I am not completely mistaken the encryption lacks a proper randomization and therefore is susceptible to a replay attack.

Who would prevent an attacker from intercepting an encrypted cookie and sending the encrypted packet a second time, not bothering that she does not know the key - since she already has the encrypted version and could deduce the meaning from context?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions