Post #4311259
2026-05-28 12:18 UTC
A RIPE Atlas probe could have been enough to hijack a RIPE NCC user's next login, giving full access to the member portal, including the RPKI dashboard and the RIPE Database.
I discovered a session fixation vulnerability in RIPE NCC's single sign-on: the session token was not rotated on login. Two ways to exploit it: a new XSS in RIPEstat through DNS NS records, or a free Atlas probe. Anyone with a free RIPE NCC account can host a probe, approved automatically. Installing a web server and serving one HTML page was all it took.
This builds on my earlier posts on the XSS+CSRF exploit chain and session token exposure through CAA misconfigurations: https://mxsasha.eu/posts/ripe-ncc-session-fixation/
The vulnerability was fixed within 20 days. This all took place before my #RIPE92 talk from last week, only some of it made it into that talk. More structural fixes are pending.
Replies (0)
No replies.