Skip to content
This repository has been archived by the owner on Feb 7, 2024. It is now read-only.

XSRF vulnerability #7

Open
luelista opened this issue Nov 7, 2018 · 1 comment
Open

XSRF vulnerability #7

luelista opened this issue Nov 7, 2018 · 1 comment

Comments

@luelista
Copy link
Collaborator

luelista commented Nov 7, 2018

I noticed that FreshDNS is vulnerable to Cross-Site Request Forgery, allowing an attacker to e.g. delete all zones on your server if they can get you to load a website containing their javascript while you're logged in to FreshDNS in the same browser.
It is fixed (hopefully) in my merge request #6

@AngeliqueDawnbringer
Copy link
Collaborator

Will test for this when I have time. Going through the code as we speak to see if I can find anything "weird". I will push some "dirty" fixes like the auto-md5 to sha1/sha512 and make sure those are pushed to this as well. I'll also add all the DNSSEC related information etc. when I find some spare time.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants