Results 1 to 4 of 4
Thread: forum security
-
03-19-2008, 03:57 PM #1Banned
- Join Date
- Mar 2008
- Location
- northern va
- Posts
- 298
forum security
anyone notice how when u close browser/end session it doesn't log you out. AKA you come back to site after a night away and yer logged in automatically? Isn't this kind of nonstandard activity for a user website. I'm not sure of the exact security implications of this forum but wouldnt it be easy for a hacker to hijack the session and take over an admins permissions or read PM's etc?
-
03-19-2008, 05:29 PM #2
If you're concerned you could just click "log out" at the end of your session.
-
03-20-2008, 10:38 AM #3Banned
- Join Date
- Mar 2008
- Location
- northern va
- Posts
- 298
gotcha, yeah i wasnt so concerned for myself, just in general the use of unlimited session-cookies... this is more a theoretical thing, for example if someone use cross site scripting and directed a cookie to their site, they could hijack the account but looking at it a little more it seems like script is disabled pretty well.
Last edited by zartan; 03-20-2008 at 11:09 AM.
-
03-20-2008, 10:41 AM #4Banned
- Join Date
- Mar 2008
- Location
- northern va
- Posts
- 298
would be cool if we could https though, then it would be a little more secure
Last edited by zartan; 03-20-2008 at 11:28 AM.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Zebol 50 - deca?
12-10-2024, 07:18 PM in ANABOLIC STEROIDS - QUESTIONS & ANSWERS