Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Developers

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-13-2007, 02:56 AM
Junior Member
 
Posts: 5
Default preauth: bug or feature ?

Hi all,

I've a script that generates preauth URL for my users to login into different webmail. For example, here is the URL for toto@domain.com:

Code:
https://zimbra.webmail.com/service/preauth?account=toto%40domain.com&by=name&timestamp=1184319241000&expires=0&preauth=31791cdfb374449e0b28ec3dc08650f5efd7f
The issue is that if your replace "toto" with "tutu", you will be able to login into tutu@domain.com's account:

Code:
https://zimbra.webmail.com/service/preauth?account=tutu%40domain.com&by=name&timestamp=1184319241000&expires=0&preauth=31791cdfb374449e0b28ec3dc08650f5efd7f
You can even change the preauth value, and you still are able to login into the account:

Code:
https://zimbra.webmail.com/service/preauth?account=tutu%40domain.com&by=name&timestamp=1184319241000&expires=0&preauth=31791cdffd7f
It seems that the server side script (/service/preauth) does not calculate correctly the hmac-sha1 or does not take care of it.

Am I doing something wrong ?

Regards
Reply With Quote
  #2 (permalink)  
Old 07-17-2007, 05:45 PM
Zimbra Employee
 
Posts: 26
Default

Have you made sure to clear all cookies, cache, auth sessions, and the like? It could be that even though you left the inbox for toto, because you are directly putting tutu in there, it's logging you in.
Reply With Quote
  #3 (permalink)  
Old 07-17-2007, 11:11 PM
Junior Member
 
Posts: 5
Default

I tested it with a new opened browser. Once I'm logged with one account (eg. toto@domain.com), I am able to see all accounts of the domain (tutu@domain.com, titi@domain.com, tata@domain.com, ....) by just changing the url parameter.

I don't use the latest 4.5 version of Zimbra OSS. I'll try with the latest one, and the NE edition ...
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.