Re: Security Issue "token" "authToken" hijacking

2017-11-20 Thread Mike Jumper
On Nov 20, 2017 20:07, "Thiago Araújo" wrote: Hello everyone, I will be very brief in my story. We recently tried to implement guacamole for about 2500 users or more. However, guacamole did not respond well to pen testing. The pen testing team has found a way to hijack the authToken, and connec

Security Issue "token" "authToken" hijacking

2017-11-20 Thread Thiago Araújo
Hello everyone, I will be very brief in my story. We recently tried to implement guacamole for about 2500 users or more. However, guacamole did not respond well to pen testing. The pen testing team has found a way to hijack the authToken, and connect to the guacamole interface of any other com