Open Server Watch
No vulnerabilities could be found in Sitting Duck's installation of Open Server Watch, even after quite a bit of scrutiny.
An overview of some of the issues we looked at:
- The request parameter in the login form is an arbitrary redirect (lame),
- Cookies are not HTTP only, which could allow stealing if we found a XSS attack,
- CSRF protection is done by adding half of the SessionID to the URL which is not optimal, however, this seems to be effective at this point.