Current time: 06-02-2024, 06:07 AM Hello There, Guest! (LoginRegister)


Post Reply 
PMA Security vulnerability ?
Author Message
joximu Offline
helper
*****
Moderators

Posts: 7,024
Joined: Jan 2007
Reputation: 92
Post: #6
RE: PMA Security vulnerability ?
@RatS:
the blowfish_secret has nothing to do with the access to the database - it's just the encryption key for the cookie session. If the session has expired then you must login in any case - during the session it's ok if you have the crypted cookies in the browser...
I changed the blowfishsecret and all I had to do is login again into pma...

That's why I thought that if I have the cookies from BeNe I could try to get the passwords (no need to be on the same day) and then I get maybe the login infor for his pma...
(I have the key - is default -> I should be able to decrypt the cookie session data.

Or am I totally wrong...??

Cheers
05-31-2007 03:23 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
PMA Security vulnerability ? - BeNe - 05-30-2007, 07:11 PM
RE: PMA Security vulnerability ? - joximu - 05-30-2007, 07:47 PM
RE: PMA Security vulnerability ? - BeNe - 05-30-2007, 11:34 PM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 02:22 AM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 02:40 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007 03:23 AM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 07:30 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 08:33 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 10:17 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 11:22 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 05:07 PM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 11:12 PM
RE: PMA Security vulnerability ? - raphael - 06-01-2007, 10:21 AM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)