Last modified: 2010-05-01 20:18:56 UTC

Wikimedia Bugzilla is closed!

Wikimedia has migrated from Bugzilla to Phabricator. Bug reports should be created and updated in Wikimedia Phabricator instead. Please create an account in Phabricator and add your Bugzilla email address to it.
Wikimedia Bugzilla is read-only. If you try to edit or create any bug report in Bugzilla you will be shown an intentional error message.
In order to access the Phabricator task corresponding to a Bugzilla report, just remove "static-" from its URL.
You could still run searches in Bugzilla or access your list of votes but bug reports will obviously not be up-to-date in Bugzilla.
Bug 23371 - Special:Userlogin form is not token protected
Special:Userlogin form is not token protected
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
All All
: Normal critical (vote)
: ---
Assigned To: Platonides
Depends on:
  Show dependency treegraph
Reported: 2010-05-01 20:15 UTC by Platonides
Modified: 2010-05-01 20:18 UTC (History)
0 users

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description Platonides 2010-05-01 20:15:10 UTC
The Special:Userlogin forms for login and account creating is not token 
protected with a session, which caused bug 23076. However, r64677 only 
fixed it for login (which is the most critical due to $wgAllowUserJs).

The hole remains for "E-mail me my password", "Create account" and 
"Create by e-mail", with the following abuse cases:

*For wikis allowing public account creation, an attacker could create 
many accounts via proxying users, avoiding ip blocks, the anon gets 
logged in (wikis using ConfirmEdit to request a captcha for createaccount 
are protected from this).

*If the victims were logged users, the attacker could create the 
accounts by email and flood innocent parties using the wiki as gateway.

*If the victim was a sysop, the attacker could not only bypass the 
captcha protection, but also the username blacklist.

*It also provides a way to bypass the blocks and ping limit for sending 
many password resets flooding its targets.

*On private wikis an account creation by targeting a sysop may expose 
confidential information.
Comment 1 Platonides 2010-05-01 20:18:56 UTC
Fixed on r65760

Note You need to log in before you can comment on or make changes to this bug.