Our site is regularly scanned by Trustwave to ensure we comply with PCI DSS.
We accept that session cookies don't carry Card data; However, it seems that they can be hacked if the ID is easy enough to guess, also it seems that theycan help a hacker to control things.
Can Actinic use longer cookie numbers or something to cure this issue?
Quote from Trust wave:
Predictable Cookie Session IDs
The remote web application is using predictable cookie-based session IDs. Ideally, session IDs are randomly generated numbers that cannot be guessed by attackers. If the session ID is predictable, an attacker could hijack an active victim's session, allowing the attacker to interact with the server as though they were the victim. If the session ID is used to track the state of authentication, the session ID of an authenticated user could be guessed, bypassing any need for a username or password.
This software needs to be either configured or modified to generate random session IDs.
If this host is running ColdFusion, enable the 'Use UUID for cftoken' option on the Settings page in ColdFusion Administrator to produce CFTOKEN values with sufficient entropy as opposed to the 8-digit numbers that are used by default.
End Quote
We accept that session cookies don't carry Card data; However, it seems that they can be hacked if the ID is easy enough to guess, also it seems that theycan help a hacker to control things.
Can Actinic use longer cookie numbers or something to cure this issue?
Quote from Trust wave:
Predictable Cookie Session IDs
The remote web application is using predictable cookie-based session IDs. Ideally, session IDs are randomly generated numbers that cannot be guessed by attackers. If the session ID is predictable, an attacker could hijack an active victim's session, allowing the attacker to interact with the server as though they were the victim. If the session ID is used to track the state of authentication, the session ID of an authenticated user could be guessed, bypassing any need for a username or password.
This software needs to be either configured or modified to generate random session IDs.
If this host is running ColdFusion, enable the 'Use UUID for cftoken' option on the Settings page in ColdFusion Administrator to produce CFTOKEN values with sufficient entropy as opposed to the 8-digit numbers that are used by default.
End Quote
Comment