Google

Home
Most Popular
Petals

|
*
2006/02/01
 21:26:21

BlackBoard session reuse

This was posted to BugTraq today. My response? Figures. Seems they must still have the same crew working on sessions.

#
By Kruck on 2006/02/01 at 22:45:27

you guys still use that?

#
By Jeremy on 2006/02/01 at 22:54:46

Blackboard? Yea. It doesn't seem to be vulnerable to that specific one though. And the session keys aren't obvious in the 1-100k space. I'm currently minimally concerned with their session key security, primarily due to the fact we use webserver passthrough authentication. That means you can't even get to the system's native session keys unless BethelAuth has already authenticated you, and those keys are very well seeded, tied to IP if possible, and held as "expired" in the database for quite a while to prevent reuse.