A Cookie Secret Named After Itself Let Researchers Impersonate 95 Users and Walk Right Past Entra ID MFA
Researchers at Resecurity logged into 95 employee accounts on a supply chain platform without a single password, MFA prompt or valid Microsoft login. The c
Researchers at Resecurity logged into 95 employee accounts on a supply chain platform without a single password, MFA prompt or valid Microsoft login. The culprit was a session cookie whose signing secret was its own name, a placeholder that apparently nobody ever replaced.
The target, found during an authorized test, was a yard management system (YMS) used to coordinate trucks, trailers and yard operations. Admins were among the accounts taken over, GBHackers reports.
Strong front door, cardboard side door
On paper, the stack looked solid. Sign-in ran through Microsoft Entra ID SSO with RS256 tokens, on a Node.js, Express and Next.js backend with Prisma, PostgreSQL, request validation and parameterized queries. Swagger docs at /api-docs/ laid out 251 API routes.
But every authenticated request also leaned on a second, custom cookie called session_secret_example. Instead of a random server-side session ID, it held an HMAC-SHA256 signed copy of the user's database ID. Those IDs were hardly secret. They showed up in /api/v1/auth/me, user directory APIs and the createdBy and updatedBy fields on records.
The HMAC key was the literal string session_secret_example. Researchers recovered it by checking roughly 110 likely candidates offline against a known cookie and signature pair.
A signature is not a session
The application only verified that the signature was valid. It never checked that the cookie mapped to a live server-side session or a recent Entra ID sign-in, so a correctly signed public user ID counted as proof of identity.
Forged sessions worked for 95 of 241 user IDs tested, spanning operators, technicians, yard staff and administrators, each with role-matched read and write access. An admin-level forgery pushed through a state-changing API request. To make matters worse, /api/v1/auth/me also handed back the user's Entra refresh token.
The technique maps loosely to MITRE ATT&CK T1550.004, web session cookie abuse, though here nothing was stolen or replayed. The cookies were simply minted. It is a cousin of the AitM kits that sidestep OTP-based MFA, except no phishing page was needed, and a reminder that patching the identity provider, as with the recent Entra ID flaw, does nothing if the app bolts its own trust layer on top.
The recommended fixes are unglamorous: rotate signing secrets, invalidate sessions and refresh tokens, stop returning refresh tokens from APIs, review logs, switch to random server-side session IDs with short lifetimes, and require step-up authentication for sensitive actions. The company had paid for the hard part. A default string undid it.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free