When bringing attention to the session termination security issue present with Ruby on Rails’ CookieStore and Django’s cookie-based session storage mechanism, one of the common questions I get is “Who is using it?”
Well, I did some digging and have the following list of 1,897 websites for your review. These are Rails sites only (before version 4.0, and not including Rails sites that encrypt their cookie values). This is not an exhaustive list, and there is future work to be done in detecting remotely the use of Rails’ CookieStore with encrypted values as well as the presence of Django’s cookie-based storage mechanism.
This Insufficient Session Expiration weakness (WASC-47) is pretty common I found, and it is especially bad when the site does not use SSL. Many of the websites and tools we use store the session hash on the client side, including the applications Redmine, Zendesk, and Spiceworks.
If you don’t have access to the app’s source code, you may be able to figure out if the site you are visiting is using Rails’ CookieStore (before version 4.0 due to its encrypted cookie values) by checking for the string “BAh7″ at the beginning of the value of any of the cookies. A SHODAN search will reveal tens of thousands of these apps: www.shodanhq.com/search?q=BAh7*
Contact me if you are on the development team of any of the following websites and need help switching.
Pingback: How to Verify the Rails CookieStore Session Termination Weakness | MaverickBlogging
Pingback: Ruby on Rails CookieStore Vulnerability Plagues Prominent Websites | RobertJGraham.com
Pingback: Mobile Security Unfiltered » Ruby on Rails CookieStore Vulnerability Plagues Prominent Websites
Pingback: WarnerBros.com and Kickstarter.com Exposed Due to Ruby on Rails Vulnerability | Cyber Security Infotech(P) Ltd
Pingback: Zehntausende Ruby-on-Rails-Seiten per Cookie-Klau kompromittiert | Klaus Ahrens: News, Tipps, Tricks und Fotos
Pingback: Más de mil sitios expuestos por vulnerabilidad en Ruby on Rails | Hackerss.com
Pingback: Kickstarter, Urbanspoon and Warner Bros among 2,000 sites at risk from “impersonators”IT Security News aggregated by IT Security expert Sorin Mustaca | IT Security News aggregated by IT Security expert Sorin Mustaca
Pingback: IT Secure Site » Blog Archive » Kickstarter, Urbanspoon and Warner Bros among 2,000 sites at risk from “impersonators”
Pingback: Ruby on Rails CookieStore Vulnerability Plagues Prominent Websites « Cyber Security Aid
Pingback: Nearly 2000 Sites Vulnerable to Ruby on Rails Cookie Problem | Threatpost | The First Stop For Security News
Pingback: Linux Outlaws 329 – A Problem with the Drupal Core | Sixgun Productions