Forum Discussion
flomkrl_29950
Nimbostratus
Nov 27, 2008Cookie steal risk ?
Hello,
If an other user catch the BIGIP cookie, is it able to access to the application without authentification ? , i'm refering to IRULE ClientAuthUsingHTMLForms (http://devcentral.f5...
Hamish
Cirrocumulus
Dec 02, 2008A couple of small observations about cookies... And this iRule.
1. I don't think the cookie is set aas a 'secure' cookie. So in theory it's vulnerable to attack if it is presented to the site acorss an un-encrypted session
2. The cookie actually contains data... Encrypting it is of dubious use. No encryption of the cookie contents will stop someone from stealing it. It would only stop someone from looking at it & changing it themselves.
Note that in an iRule you're probably not going to get away from 2. Normally you'd keep a session table with the info on the web server and the cookie would be a random value key to look that info up (e.g in a hash table). But iRules don't really provide for that level of control.
Short answer is that there's nothing there to guarantee security. YMMV.
Hamish.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects