Welcome Guest ( Log In | Register)



2 Pages V   1 2 >  
Reply to this topicStart new topic
> Cookie Security Vulnerability, If you're using IE to login
dodgerblue
post Apr 26 2005, 05:59 PM
Post #1


Super Member
*********

Group: Members
Posts: 270
Joined: 11-April 05
From: 10 inches from the computer screen
Member No.: 5,518



Problem:

The cookie for admin is set by default to one month for most scripts. This is dangerous because anyone can enter a certain script (which I won't paste here), and IE will auto-correct it, sending information to that person, who can then change the UID and log in to the site as admin!!

Solution:

If you're using IE to login to, clear your cookies, it's not too late!

Then, switch over to Mozilla. smile.gif You know you want to...
Go to the top of the page
 
+Quote Post
GM-University
post Apr 26 2005, 09:45 PM
Post #2


Super Member
*********

Group: Members
Posts: 287
Joined: 23-February 05
Member No.: 3,945



This is for what, phpBB, IPB, other? Or for all IE browsers, in that case it would mean anyone using ti could access it anyways...
Go to the top of the page
 
+Quote Post
dodgerblue
post Apr 26 2005, 10:02 PM
Post #3


Super Member
*********

Group: Members
Posts: 270
Joined: 11-April 05
From: 10 inches from the computer screen
Member No.: 5,518



Last checked, yes, phpBB, Geeklog, Xoops... etc. All those scripts that lots of people here in this forum use... It's a IE exploit to do with the way IE reads vbscript tags.
Go to the top of the page
 
+Quote Post
CrashCore
post Apr 26 2005, 10:06 PM
Post #4


Super Member
*********

Group: [HOSTED]
Posts: 225
Joined: 8-April 05
Member No.: 5,385



Who uses Internet Explorer anymore anyways? The only reason people use it anymore (since Firefox) is because of Micro$oft's brainwashing tongue.gif Since when does IE auto-correct stuff without your consent? Where will Micro$oft stop?
Go to the top of the page
 
+Quote Post
Shadow
post Apr 27 2005, 02:26 AM
Post #5


Super Member
*********

Group: Members
Posts: 290
Joined: 6-September 04
Member No.: 1,029



And Microsoft gets worse.. That's not good because I still use IE(mainly cuz this isn't my comp to install things on). I guess it's a good thing no one has discovered my site yet since I change it so gawd damn much! But it's still an issue for the other 4 people who use this computer. Thanx for the info, I will be sure to inform the owner of this comp(my dad) and get him to switch to mozilla asap!
Go to the top of the page
 
+Quote Post
dodgerblue
post Apr 28 2005, 02:47 PM
Post #6


Super Member
*********

Group: Members
Posts: 270
Joined: 11-April 05
From: 10 inches from the computer screen
Member No.: 5,518



lol Shadow, actually, you can download Firefox for free here: http://www.mozilla.org/products/firefox/central.html

Crashcore - yeah, when I checked my stats, about 80% of my visitors were on Firefox, 5% on Opera and only 12% on IE. biggrin.gif

Let's hope more people catch on!! smile.gif
Go to the top of the page
 
+Quote Post
Odyssey
post Apr 30 2005, 06:46 PM
Post #7


Premium Member
********

Group: Members
Posts: 150
Joined: 29-March 05
Member No.: 4,988



Well, thanks for notifying us!

I currently run phpBB boards, and now have them updated accordingly to 2.0.14 . Also it seems that this problem is with any browser, but I use Mozilla Firefox anyways.

Also, any one that still uses Internet Explorer, you should make the switch to Mozilla Firefox as soon as possible, I gurantee that you will like the switch, and to those of you who have toolbars, and spyware in Internet Explorer, you will not notice them in Firefox smile.gif
Go to the top of the page
 
+Quote Post
MarCrush
post Jun 2 2005, 02:08 AM
Post #8


Super Member
*********

Group: Members
Posts: 203
Joined: 2-June 05
From: Why would you want to know?
Member No.: 7,778



QUOTE(CrashCore @ Apr 26 2005, 03:06 PM)
Who uses Internet Explorer anymore anyways?  The only reason people use it anymore (since Firefox) is because of Micro$oft's brainwashing tongue.gif  Since when does IE auto-correct stuff without your consent?  Where will Micro$oft stop?
*



Maybe in IE 7 (Microsoft is making right now) will stop this. But who knows. Most people use IE and it is impossible for everyone to switch over to Mozilla. Some sites don't even look good in Mozilla but yet again every user has their perfences.
Go to the top of the page
 
+Quote Post
Keeper
post Jun 24 2005, 09:31 PM
Post #9


Advanced Member
*******

Group: Members
Posts: 143
Joined: 30-January 05
Member No.: 3,507



Everyday before i turn off my comp, i clear cookies... rolleyes.gif And i think it helps wink.gif




_________________________________________
Keeper, Sons of the Dragon http://mercenaries.net.ru