Forum Discussion
jksingh_44237
Nimbostratus
Jan 04, 2010The remote load balancer suffers from an information disclosure vulnerability at port 80 and 443
I am looking a solution for this issue.....
I have BIGIP (BIG-IP 9.3.1 Build 37.1)
Port http (tcp/80)
Synopsis :
The remote load balancer suffers from an i...
Hamish
Cirrocumulus
Jan 05, 2010I got an answer from F5...
Looks like the un-encrypted cookie is safe IF you're not performing 'Match Across Pools' or match across services (Or VS) for persistence... if you are, then the rules change somewhat.
Match across service or match across VS will let an attacker alter the port specified by the poolmember. Match across pools is more open. The attacker can specify any poolmember they like (I'm paraphrasing what F5 told me).
Hmm... Inherently unsafe in certain situations... (i.e. your secure website can be compromised by an insecure config on a non-secure VS). I've requested a CR to change the default behaviour to encrypting all persistence cookies and a SOL note to ensure people know about it...
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
