?
avatar paragonie-scott paragonie-scott - open - 16 Dec 2015
avatar paragonie-scott paragonie-scott - change - 16 Dec 2015
Title
[3.4] Session IDs are Predictable
[3.4] Session Tokens (for spam prevention? looks like CSRF) are Predictable
avatar mbabker mbabker - reference | d3e5d75 - 16 Dec 15
avatar mbabker
mbabker - comment - 16 Dec 2015

See #8714

Unless there are characters in JUserHelper::genRandomPassword() that for whatever reason couldn't validate as a CSRF token that occasionally is included as part of a URL, just using that (which uses random_bytes()) is good enough.

avatar paragonie-scott
paragonie-scott - comment - 1 Jan 2016

Yeah, I think genRandomPassword() is the way to go here.

avatar brianteeman brianteeman - close - 8 Jan 2016
avatar mbabker mbabker - change - 8 Jan 2016
Status New Closed
Closed_Date 0000-00-00 00:00:00 2016-01-08 09:46:54
Closed_By mbabker
avatar mbabker mbabker - close - 8 Jan 2016
avatar brianteeman brianteeman - change - 8 Mar 2016
Labels Added: ?

Add a Comment

Login with GitHub to post a comment