rabbibotton / clog

CLOG - The Common Lisp Omnificent GUI
1.49k stars 102 forks source link

handle-new-connection seems insecure given that connection ids are serial numbers #174

Closed shakatoday closed 2 years ago

shakatoday commented 2 years ago


An attacker can first get current generated ID (which are now serial numbers) to know current possible ids range. Then, the attacker could steal others' connections with ws://HOST/clog?r=CONNECTION_ID.

rabbibotton commented 2 years ago

Will address that this week.

rabbibotton commented 2 years ago

I updated how the ids are generated. Ideally you are also using https when security an issue as well.