Sasha Romijn · May 28, 2026
RIPE NCC session fixation: poaching logins with an Atlas probe
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
RIPE NCC’s single sign-on did not rotate session tokens on login, leaving 12000 Atlas probe hosts in a position to compromise other RIPE NCC users’ logins. A single link click planted a session token in a target’s browser. When that target next logged in to a RIPE NCC service, possibly much later, the attacker could access their account. An XSS variant did the same regardless of…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.