4 ms·
I hope you've managed to fix this, because this is an obvious security issue. A long token is used precisely because it is long and unguessable. The shortened U
by mediumdeviation 5y ago
I hope you've managed to fix this, because this is an obvious security issue. A long token is used precisely because it is long and unguessable. The shortened URL is subject to enumeration attacks which can be used to hijack accounts.
- ______- 5y ago> A long token is used precisely because it is long and unguessable This. So much fun can be had by enumerating link shortener URLs. I've experimented with enumerating some services' URL schema. Most of the time the link pointed to innocuous things like Amazon affiliate links or whatnot. Sometimes you would find interesting content that made you go 'wow!', but that was very rare.
- chias 5y agoYeah. When I stumbled across this I had some conversations, with the net result that URLs containing authenticator tokens are no longer shortened :)
- jedberg 5y ago> because this is an obvious security issue Not really. Usually password reset tokens are only valid for 10 or 15 minutes. With some basic rate limiting, you can stop a single actor from accessing more than one of those links in 15 minutes. And even if they work around that, you just ask the user to verify their email address when they click on the link. Being able to enumerate the reset tokens and guess the right email address at the same time is highly unlikely.
- jonny_eh 5y agoI doubt they implemented rate limiting though.
- read_if_gay_ 5y agoHere’s some more baseless guesswork: I am absolutely certain they did.
- jonny_eh 5y agoI said "I doubt", you said "I am absolutely certain". Can you tell the difference?
- urbandw311er 5y agoI doubt he can
- read_if_gay_ 5y agoEffectively there's no difference, both statements are equally worthless.
- qu4z-2 5y agoOn the URL shortener, or on the password reset token endpoint? Because only one of those will save you.
- mewpmewp2 5y agoVerifying their e-mail address would be useless as attacker would already know the e-mail. Attacker knowing some existing user email will go to "forgot password" view and type in the e-mail for the user they plan to attack. Then after will start bruteforcing the token. It is highly unlikely they had rate limiting because they had long tokens there for a reason and most frameworks like Laravel for example which provide similar forgot password feature won't by default rate limit those tokens or at least haven't in the past. I am not up to date with current version of Laravel and I think it may be using signed urls instead. Which would also be obviously terrible if shortened. So the original team who built forgot pw didn't expect someone in the future to start shortening those urls, so it is unlikely they figured rate limiting to be necessary in this case. It would require in most cases conscious decision making and effort to specifically rate limit token guesses, likely to be out of scope. Catch all rate limiting by IP wouldn't work either because it would be arbitrary to use botnet to bruteforce. But in the OP example the e-mail/user was already in the url so included with the shortened url. In this case hacker could just try random short urls until they hit something and due to redirection also immediately know the e-mail.
- jedberg 5y ago> Verifying their e-mail address would be useless as attacker would already know the e-mail. How? Everything you said is true for the implementation that was listed, but my point was short URLs for password reset aren't always bad, if other mitigations are in place, which should be in place anyway (rate limiting requests for password reset URLs and requiring verification of the email address).
- rot13xor 5y agoThe attacker would start out with a targeted user's email or login to the site. A personal email address usually is usually public. Start the password recovery process. Use a botnet to try different shortened links. A rate limit on password reset for an account would help if the attacker had low probability of success before the reset link expired, but the attacker can cycle between multiple target accounts.
- 5y ago
- robertlagrant 5y ago> you can stop a single actor It's not just unattached performers who are the threat. People of every relations hip status and profession could be attacking.
- justinator 5y agoWell, one more place and a simple base 36 alpha/numeric shortened token like this can represent a number up to around two billion so good luck with the enumeration attack - especially if you have a reasonable rate limiting scheme for requests. 2FA tokens are usually even simpler.
- nine_k 5y agoWell, no. Suppose you have 64-bit one-time identifiers for password reset links. With base-85 encoding, it's 11 characters, short enough to even type manually. I suppose a password-reset link should expire within an hour. Scanning the entire 64-bit space in an hour in search of a working password-reset link is infeasible: rate-limiting will prevent it, and monitoring will warn about the attempt. A feasible attack vector could be on the generation algorithm, but I suppose a good link shortener won't use a simple predictable RNG.
- zinekeller 5y ago> With base-85 encoding ... and you lost your argument. There's a reason why there's a variant of Base64 designed for URLs.