NOVELL FORUMS

 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 24-Jul-2008, 02:46 PM
Junior Member
 
Join Date: Jul 2008
Posts: 2
alindell is on a distinguished road
Default framed website session security concern

We are using AM to SSO into our web portal (Portal), and subsequently access another website (F-Website) within an iframe of Portal.

The problem is that we can't kill F-Website's session when a user logs out of the portal, but does not close the browser. So, if this happens on a shared computer, and another person goes directly to an inner page of F-Website, they now have access to the previous user's account. I'll break it down into a step by step scenerio:

On a shared computer:
  1. User "A" logs into Portal.
  2. User "A" navigates to F-Website within an iframe of Portal.
  3. User "A" logs out of Portal (but does not close the browser).
  4. User "B" logs directly into a F-Website inner page (bypassing a login screen).
  5. User "B" will then have access to User "A"s F-Website account.

Note: If User "B" accesses F-Website through Portal, User "A"s session data is destroyed before User "B" gets into it. We could do this because we can pass the user name from Portal to F-Website so that it can compare the session username to the passed username, and see they are different. But, if User "B" goes directly into F-Website, this isn't possible.

This scenerio is unlikely, but still possible. So, we need to know if there's a built-in method to help with this issue.

Possible fix: Add a hidden frame in the Access Manager "logged-out" page that opens F-Website's logout page. Would this hack work without side effects? Is there a better method?

Thanks,
Anders
Reply With Quote
 


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 03:28 AM.


© 2007 Novell, Inc. All Rights Reserved.

SEO by vBSEO 3.1.0