Search found 7 matches

by sugardaddyz
Thu Sep 05, 2019 10:07 pm
Forum: Open Source Nagios Projects
Topic: Cross Frame Scripting XFS
Replies: 5
Views: 1056

Re: Cross Frame Scripting XFS

Hi Scott, When accessing Nagios core webpage. A basic authentication box will pop up, then we will login to reach nagios core homepage. We tried this using an iframe, we are able to capture the basic authentication box pop up too. If we enabled xframe deny all on httpd, nagios core webpage willl not...
by sugardaddyz
Thu Aug 29, 2019 10:20 pm
Forum: Open Source Nagios Projects
Topic: Concurrent Login
Replies: 3
Views: 683

Re: Concurrent Login

Is this feature available in Nagios XI?
by sugardaddyz
Thu Aug 29, 2019 10:15 pm
Forum: Open Source Nagios Projects
Topic: User Session timeout
Replies: 4
Views: 1317

Re: User Session timeout

Thank you Scott.

Appreciate for the fast response. :D
by sugardaddyz
Thu Aug 29, 2019 10:13 pm
Forum: Open Source Nagios Projects
Topic: Cross Frame Scripting XFS
Replies: 5
Views: 1056

Re: Cross Frame Scripting XFS

Using Nagios Core 4.4.3 The team noted that it was possible to capture the login page of the application within a HTML frame of another page as well as all the keystrokes that are entered by the user. In addition, it was also possible to authenticate the web application within the HTML frame. The te...
by sugardaddyz
Wed Aug 28, 2019 11:36 am
Forum: Open Source Nagios Projects
Topic: Cross Frame Scripting XFS
Replies: 5
Views: 1056

Cross Frame Scripting XFS

Hi guys,

Recently our security team has detected the above vulnerability for Nagios Core monitoring webpage. Is there an existing solution we can apply to address that?

Thank you
by sugardaddyz
Wed Aug 28, 2019 11:27 am
Forum: Open Source Nagios Projects
Topic: User Session timeout
Replies: 4
Views: 1317

User Session timeout

Hi guys,

How can I add a user session timeout? So user will be logged out after a period of inactivity and is required to login again.
by sugardaddyz
Wed Aug 28, 2019 11:24 am
Forum: Open Source Nagios Projects
Topic: Concurrent Login
Replies: 3
Views: 683

Concurrent Login

Hi guys, Recently our security team has flagged out the below: A single user account is permitted to login repeatedly to maintain multiple active sessions at a time. Concurrent sessions increase the chances of a user being unable to detect whether his account has been compromised. It also allows an ...