Skip to content

Harden A07 Weak Session IDs Low - #260

Open
tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-weak-id-low-complete
Open

tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-weak-id-low-complete

Conversation

@tobymoreno

Copy link
Copy Markdown

Mapping

  • challenge: Challenge-9-Weak-Session-IDs-Low
  • OWASP category: A07:2025 Authentication Failures
  • vulnerable snippet: incrementing session counter used directly as dvwaSession
  • source evidence: help text states the cookie value is very obviously predictable

Summary

  • replace the predictable counter with a 256-bit random identifier
  • scope the cookie to the Weak Session IDs path
  • add Secure, HttpOnly, and SameSite=Strict attributes
  • add focused pytest metadata and assertions for the vulnerable snippets and secure replacement

Verification

  • focused Python checks passed
  • PHP syntax check passed in Colima
  • two live POST requests produced distinct 64-character hexadecimal identifiers
  • both live Set-Cookie responses included expiry, scoped path, Secure, HttpOnly, and SameSite=Strict
  • git diff --check passed
  • signed DCO commit

This PR intentionally targets only the Low level so its CTF score identifies whether the previously incomplete cookie hardening was a remaining solve.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  1 / 108 pts  (1%)

1 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 3ba3372 · scoring run

🎉 Your result is on the leaderboard — see where you rank! 🏆

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant