This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Sentora relying too much on Client data
#2
RE: Sentora relying too much on Client data
(06-17-2015, 02:11 AM)Droppy Wrote: Hello dear community who are working all day for making a web a better place.

Basically is this: Sentora backend is relying (trusting) too much on frontend data to process requests and others.

Example of that is Email, example:

Create a new email account, but on domain you right click and select another domain which is pointed to your host.

Let's think about this schematics:

User 1's domains: abc.com , cde.com
User 2's domains: hax0r.com

User 2, wanting to sabotage User 1, discover that X domain is abc.com, and wants to create an email there (such as hacked@abc.com or hacked@cde.com), so user inspect element and changes values. Backend doesn't verify if the domain is from the user or not, it just clear the entrance, and the email is created.

There's other examples such as selecting subdomain and others, but it's the same concept.

Cya

This is true.

Should be fixed.
My Sentora Resources
[Module] Mail Quota Count | Vagrant Box with Sentora

[Image: vanguardly-logo-micro.png]
Graphic and Web Design. Development.
www.vanguardly.com


Reply
Thanks given by:


Messages In This Thread
RE: Sentora relying too much on Client data - by apinto - 06-17-2015, 05:29 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
Update redirect to Sentora login to an error page if a sub domain does not exist TGates 3 3 ,802 11-14-2024, 11:49 AM
Last Post: TGates
Need Sentora HELP ? Alemiz 4 12 ,924 10-26-2018, 04:09 PM
Last Post: republicus
Sentora Feedback and Ideas Xversion 10 32 ,832 10-28-2017, 06:49 AM
Last Post: TGates

Forum Jump:


Users browsing this thread: 1 Guest(s)