2019-10-19 - Re: [GRASE-Hotspot] CoovaChilli Challenge Parameters Problem

Header Data

From: Tim <ti***8@gmail.com>
Message Hash: 60182c5f8fc22eb21482b99f4bd5dd8ca0e9f86d8bffba666935f89d72d252e8
Message ID: <CAESLx0+oTs5YO7qX4ykDD21GfzKT3-yuKFAp5S0R0ippvnyu8g@mail.gmail.com>
Reply To: <c0d652a1-9f34-453c-81ad-249f3e94b09b@grasehotspot.org>
UTC Datetime: 2019-10-19 18:18:39 UTC
Raw Date: Sun, 20 Oct 2019 11:18:39 +1000

Raw message

Hi Sergen

Unfortunately, the challenge value will continue to change as time goes on.
This is to prevent replay attacks and other such things. However, if you're
using the JS login page, it should already be fetching a new challenge
before it submits the login attempt. Are you using the JS page, or the
plain text version?

Regards

Tim

On Sun, 20 Oct 2019 at 00:30, Sergen Çolak <se***7@gmail.com> wrote:

> Hello everybody,
> I have a question about Coovachilli. The link to the first time my PHP
> Page was loaded,
>
> http://192.168.80.1/admin/uam/hotspot?res=notyet&uamip=192.168.80.1&uamport=3990&challenge=8117e6bf4eb10d19edf8d47af8237bdd
> When I look at http://192.168.80.1:3990/json/status
> {"version": "1.0", "clientState": 0, "challenge":
> "8117e6bf4eb10d19edf8d47af8237bdd" ....
> The challenge value that appears in Json / status changes when I do not
> login for a certain time. And when I try to login, I get res = failed even
> though my username and password are correct. The Challenge mismatch in the
> Form, which appears to be exactly in Json. Can I prevent the challenge
> value from changing?
> Sorry for the bad English. Thank you.
>
> --
> This mailing list is for the Grase Hotspot Project http://grasehotspot.org
> ---
> You received this message because you are subscribed to the Google Groups
> "Grase Hotspot" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to gr***e@grasehotspot.org.
> To view this discussion on the web visit
> https://groups.google.com/a/grasehotspot.org/d/msgid/grase-hotspot/c0d652a1-9f34-453c-81ad-249f3e94b09b%40grasehotspot.org
> <https://groups.google.com/a/grasehotspot.org/d/msgid/grase-hotspot/c0d652a1-9f34-453c-81ad-249f3e94b09b%40grasehotspot.org?utm_medium=email&utm_source=footer>
> .
>

Thread