RSSAmplifier

Sasha Romijn · May 28, 2026

RIPE NCC session fixation: poaching logins with an Atlas probe

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

RIPE NCC’s single sign-on did not rotate session tokens on login, leaving 12000 Atlas probe hosts in a position to compromise other RIPE NCC users’ logins. A single link click planted a session token in a target’s browser. When that target next logged in to a RIPE NCC service, possibly much later, the attacker could access their account. An XSS variant did the same regardless of…

Read on mxsasha.eu

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.