![]() |
Hi.
For security reasons, I would make the adminCP cookie-aware; in other words, how could I make me already known when logging to the AdminCP without retypeing user/pw any new session ? I wrote 'for security reasons'.... YES! Simply, I would make the admin pw change once a couple of days, so I only need to know the new (randomly generated) one only once and don't remember it, cause my browser could do it for me... What do you think about ? Bye |
Anybody ?
Bump, please! |
How about to use a shortcut?
http://...../admin/index.php?loginusername=OURNAME&loginpassword=OURP ASS |
Nice, thanks! :)
What I don't like is to have a persistent query_string with a displayed password all the time... :( How could I - for instance - preset at least the user name with cookies ? Thnx |
Just user the username string, password string isn't needed for it to autorecognize you.
|
Yes!
I tried and actually can use each Admin username to login the AdminCP without any password. Checked the $bbuserinfo and it's always me (guess from cookie infos..), but the login name can be anyone of the other admins. Could you explain me why ???? :o Thanks P.S.: just a point out. I can use ANY loginusername=dummy to directly enter the AdminCP, bypassing the login challenge page... Neither is needed an actual bb username. Very very unpredictable... Sessions.... bah!!! :paranoid: It seems unsafe, first touch... but cookies are the network security atom .... :knockedout: |
I do not like the idea of using a cookie that say "loginusername=dummy" to get in. It i stoo easy to guess your admin name or anyone elses (they are on the forum already!!). If you are going to build a login=xxx in a cookie, it should be something hard to just guess and hack. Maybe the md5 encrypted password string. Or both.
Better but not perfect. SO if this is teh way vB works now, anyone can hack almost any system just by editing their cookie file. Let's see, I wonder where the Version 3 development forums are ? |
That's not true, Jawelin. If it happened you were either already logged in or messed up your sessions.php file.
Oh and galt: http://beta.jelsoft.com/ |
FireFly, you are wrong, if you have cookies set you can login to admin control panel, by adding going to /admin/index.php?loginusername=xxx it doesn't matter what xxx is, it can be anything, doesn't have to be a user.
I verified by dumping everything from the session table in myphpadmin and then logging in. It doesn't work if you have cleared your cookies, so you still need to find a board with html enabled anywhere to steal cookies from admins. Btw, if you steal cookies you can still change email and then change password to get admin cp access, so for the endevouring hacker nothing changes :) |
[QUOTE]Originally posted by FireFly
That's not true, Jawelin. If it happened you were either already logged in or messed up your sessions.php file. |
[QUOTE]Originally posted by Issvar
FireFly, you are wrong, if you have cookies set you can login to admin control panel, by adding going to /admin/index.php?loginusername=xxx it doesn't matter what xxx is, it can be anything, doesn't have to be a user. I verified by dumping everything from the session table in myphpadmin and then logging in. It doesn't work if you have cleared your cookies, so you still need to find a board with html enabled anywhere to steal cookies from admins. Btw, if you steal cookies you can still change email and then change password to get admin cp access, so for the endevouring hacker nothing changes :) |
All times are GMT. The time now is 04:44 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|