diff options
author | Joey Hess <joey@kodama.kitenet.net> | 2008-07-22 13:17:04 -0400 |
---|---|---|
committer | Joey Hess <joey@kodama.kitenet.net> | 2008-07-22 13:17:04 -0400 |
commit | a759a864f37925e6788980ac53bd8f7c69172635 (patch) | |
tree | 1c6f09028c12d9d9e79fe0a66a1c553c764419fd /doc/bugs/ssl_certificates_not_checked_with_openid.mdwn | |
parent | 80f95cc598ed4803927662edbab113b64da28518 (diff) | |
parent | 3ac17b8328ed005406d5d4018a46e05c80a819f3 (diff) |
Merge commit 'origin/master' into tova
Diffstat (limited to 'doc/bugs/ssl_certificates_not_checked_with_openid.mdwn')
-rw-r--r-- | doc/bugs/ssl_certificates_not_checked_with_openid.mdwn | 13 |
1 files changed, 12 insertions, 1 deletions
diff --git a/doc/bugs/ssl_certificates_not_checked_with_openid.mdwn b/doc/bugs/ssl_certificates_not_checked_with_openid.mdwn index 171874951..cb4c706f0 100644 --- a/doc/bugs/ssl_certificates_not_checked_with_openid.mdwn +++ b/doc/bugs/ssl_certificates_not_checked_with_openid.mdwn @@ -22,4 +22,15 @@ For now, I want to try and resolve the issues with net\_ssl\_test, and run more > is good. > --[[Joey]] -[[!tag done]] +>> Ok, so I guess the worst that could happen when ikiwiki talks to the http +>> address is that it gets intercepted, and ikiwiki gets the wrong address. +>> ikiwiki will then redirect the browser to the wrong address. An attacker could +>> trick ikiwiki to redirect to their site which always validates the user +>> and then redirects back to ikiwiki. The legitimate user may not even notice. +>> That doesn't so seem secure to me... + +>> All the attacker needs is access to the network somewhere between ikiwiki +>> and http://joey.kitenet.net/ or the ability to inject false DNS host names +>> for use by ikiwiki and the rest is simple. + +>> -- Brian May |