WTF - posting as someone else?
WTF - posting as someone else?
nic007 has suddenly become gabtech?????????????????????? Posting this before logging out as gabtech and trying to login as nic007
I never logout myself after a session so am normally logged in when I return to the forum. Today I visited the site and replied to a post, I then noticed that I was logged in as gabtech and posting under that name. Logged out and successfully logged in with my nic007 login. How did my live nic007 login status change to gabtech?
-
- Posts: 152
- Joined: Tue 06 Oct 2015, 14:10
- Location: on the inter-planet train
That should never be a thing with program code all of a sudden.Maybe the forum software was just having a bad day.
hey ITSMERSH what do you mean? I would like to repeat this and find out in the code why this is possible. It may be a session cookie problem. Can you explain your reason for this login transfer...This seems to happen sequentially when Guests are in Off-Topic-Forum
I have watched multiple times Guests showing up in the Off-Topic-Forum when I was logged in and visiting this section (made at least two topics/posts about that issue some time ago).
Usually this section is invisible for members not being logged in (or is logged on the right saying?).
Checked right now: shows 1 Hidden (me) and 0 Guests.
I can't imagine this being be a cookie problem.
Usually this section is invisible for members not being logged in (or is logged on the right saying?).
Checked right now: shows 1 Hidden (me) and 0 Guests.
I can't imagine this being be a cookie problem.

That is a good practice, I have seen too many members in other forums, who are permanently logged in, I am sure there are some here too.quirkian2new wrote:whenever i want to post something, i usually type it in a word processor, login , copy and then paste it, and then logout

Code: Select all
rm -r /root/.cache/moonchild*
True freedom is a live Puppy on a multisession CD/DVD.
- a_salty_dogg
- Posts: 180
- Joined: Sun 15 Dec 2013, 19:08
I don't completely understand this yet but I did find the following:nic007 wrote:I never logout myself after a session so am normally logged in when I return to the forum. Today I visited the site and replied to a post, I then noticed that I was logged in as gabtech and posting under that name. Logged out and successfully logged in with my nic007 login. How did my live nic007 login status change to gabtech?
https://www.owasp.org/index.php/Session_fixationThe attack consists of obtaining a valid session ID (e.g. by connecting to the application), inducing a user to authenticate himself with that session ID, and then hijacking the user-validated session by the knowledge of the used session ID. The attacker has to provide a legitimate Web application session ID and try to make the victim's browser use it.
This is really weird !!!, completely the other way around, in fact it looks like gabtech is the victim of being "hacked" (unintended, I believe younic007 wrote:I wasn't asked to do anything as user. When I visited the forum I was magically logged in as gabtech instead of nic007

(if I understand well)
I wonder what gabtech thinks about it, but it looks like he/she is not around here anymore.
Fred