Skip to content

Session cookie sharing could bypass csswaf #5

@runxiyu

Description

@runxiyu

A bot that successfully passes the challenge could forward it on to other bots in the bot network and use it to access the page without needing to validate

While it is relatively difficult to prevent these classes of attacks altogether, the solution from Anubis and my PoC is to use the source client's IP address and other info to produce a unique-ish identifying hash, which imo is more sound than using session cookies for this

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions