Security Issue
Is it possible to force the browser to close upon logout?
The reason we are asking if this is possible is due to a potential security
breach of our vBulletin Discussion Forums.
Basically, when a user logs out, the previously viewed pages are still
cached and fully available simply by clicking the 'Back' button. I was able
to see the forums, structure, postings, even the text of sent Private
Messages... Of course all the links were dead, however the fact that the
information is still viewable is a problem.
In addition, after logging-out, the confirmation screen had a 'forum jump'
drop-down box that displayed the entire structure of the forums. This is
also a problem.
If forcing a browser close upon logout would be difficult, is there
another way to prevent the above from breaching the security of our
Discussion Forums? The seriousness of this potential security breach could
cause many of our users to be too uncomfortable to use the forums actively.
Thank you in advance...
Aloha,
Dan
|