Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
_forestfortrees
on Sept 20, 2016
|
parent
|
context
|
favorite
| on:
Pre-auth Remote Code Execution Vulnerability in Me...
Fun stuff. Serious question though: if you know the cookie signing key, can't you just mint yourself an admin session? Is the YAML vuln required to exploit this issue?
spydum
on Sept 21, 2016
[–]
I suspect no: you can sign cookies, but hopefully cookie only carries a session identifier. You'd still need to obtain a valid admin session..
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: