savannah-hackers
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Savannah-help-public] [sr #107281] Verification of account email change


From: Matt McCutchen
Subject: [Savannah-help-public] [sr #107281] Verification of account email changes is ineffective (try 2)
Date: Wed, 24 Feb 2010 19:37:53 +0000
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2) Gecko/20100220 Fedora/3.6.1-1.custom.fc12 Namoroka/3.6

URL:
  <http://savannah.gnu.org/support/?107281>

                 Summary: Verification of account email changes is
ineffective (try 2)
                 Project: Savannah Administration
            Submitted by: hashproduct
            Submitted on: Wed 24 Feb 2010 02:37:52 PM EST
                Category: Savannah website
                Priority: 5 - Normal
                Severity: 6 - Security
                  Status: None
             Assigned to: None
        Originator Email: 
        Operating System: None
             Open/Closed: Open
         Discussion Lock: Any

    _______________________________________________________

Details:

My sr #107268 was wrongly closed and I am unable to reopen it, so I am
submitting another ticket with a (hopefully) clearer explanation of the
problem.

AIUI, the goal of the email confirmation mechanism in Savannah is to prevent
a user from setting an account email address that she does not own.  It works
by sending a secret confirmation link to the new address; the user is required
to click the link to complete the change.  Savannah also sends a link to the
old address offering to cancel the change.

However, the mechanism as currently implemented does not achieve the goal
because the confirmation link can be easily derived from the cancellation link
by changing one query parameter at the end.  Hence, a user can change his/her
account email address to an address she does not own, just using the
cancellation link received at her old address.




    _______________________________________________________

Reply to this item at:

  <http://savannah.gnu.org/support/?107281>

_______________________________________________
  Message sent via/by Savannah
  http://savannah.gnu.org/





reply via email to

[Prev in Thread] Current Thread [Next in Thread]