Re: Trouble Logging On
Posted: Thu Jun 20, 2002 11:12 pm
Just a quick observation on the cookies.
I was going to post this earlier, but keept getting inturpted.
I did perform some tests earlier to mimic what you were talking about auslander. I know my understanding with cookies is fairly non-existent but I have enough knowledge to understand what is going on.
I examined the cookie while I was logged into the board and it contained 3 sections.
They were "Last Visit", "User ID" & "Password". (BTW the password & User ID are not in plain text, they are things the message board assigns so it knows who you are.)
When you click the "Log out" button "User ID" & "Password" sections are removed from the cookie, but the "Last Visit" portion stays.
I doubt that someone would be able to do that easily, it would be easier for them to attempt to guess your Password, than guess your session ID.
Well I think this problem is more of cookies getting corrupt, or possibly session IDs changing. I occasionally have a problem where I'm online and lodged in, then click on a screen and no longer logged in. It happens occasionally, and I just have to relog in.
I hope this helps explain what goes on when you log in and out.
Hopefully it didn't go over your head.
I was going to post this earlier, but keept getting inturpted.
I examined the cookie while I was logged into the board and it contained 3 sections.
They were "Last Visit", "User ID" & "Password". (BTW the password & User ID are not in plain text, they are things the message board assigns so it knows who you are.)
When you click the "Log out" button "User ID" & "Password" sections are removed from the cookie, but the "Last Visit" portion stays.
ent.Bboy wrote: Thu Jun 20, 2002 5:21 pm 4. The possibility of spoofing a session id is virtually non exist
I doubt that someone would be able to do that easily, it would be easier for them to attempt to guess your Password, than guess your session ID.
it would drop your log in going from one board to anotherauslander (imported) wrote: Thu Jun 20, 2002 11:15 am Another possibility is that you've becom5. All of the Archive message boards use exactly the same code -- and I mean THE SAME code, not different but identical, to check authentication ... so it makes no sense that
Well I think this problem is more of cookies getting corrupt, or possibly session IDs changing. I occasionally have a problem where I'm online and lodged in, then click on a screen and no longer logged in. It happens occasionally, and I just have to relog in.
I hope this helps explain what goes on when you log in and out.