Antville Project

Sunday, 17. November 2002

Login/Logout - its not a bug its a feature

This is more or less a design and cross-site-scripting issue: The login page should be a standalone page and not modifyable within the skins of a blog. Everybody with proper knowledge in DHTML, Javascript is able to logout a user and maybe forcing a subscriber to relogin on the modified blog. Redirect the username and password to another server and redirect it back to antville. If the login-page (template, snippet) is not changeable, it would be no problem at all within the login-skin. It is still possible within all skins to login, logout, and redirect, but it should not be possible within the login-skin.

In this case antville needs to step back to a central sign-on that is trustworthy.

Solution: skins/edit?proto=membermgr&name=login should be not modifyable within a blogs skin.

My point of view is, the login-procedure should be somewhat trusted and not changeable/accessable within a users skin.

Suggested workaround: never ever login on another blog. If you don't have a blog, thats mmhhh say: bad luck - or a lesson in trust - you can use mine. (o;

link (10 comments
 

The Antville Server Fund has been a great success. Thanks to everybody who contributed!
online for 8549 Days
last updated: 1/4/11, 10:22 AM
status
Youre not logged in ... Login
menu
November 2002
SunMonTueWedThuFriSat
12
3456789
10111213141516
17181920212223
24252627282930
OctoberDecember
recent
zfuture's house here is zfuture's
house
by zfuture (7/31/03, 2:59 AM)
i understand your concerns however,
i hardly can think of a solution. certainly, if the...
by tobi (7/29/03, 9:47 AM)
Found several more similar sites
listed This is getting to be quite a concern to...
by cobalt123 (7/27/03, 7:56 PM)
Second Post Alert on Referrer
bug livecatz I put this into "help" and now here:...
by cobalt123 (7/26/03, 7:14 PM)
well it's not easy to
find from here, anyway. think we should include a link,...
by tobi (7/24/03, 11:25 AM)
So finally I found
the helma Bugzilla - stupid me.
by mdornseif (7/24/03, 10:28 AM)
clock not that it's particularly
earthshattering but the antclock is running slow by about 15...
by kohlehydrat (7/23/03, 8:25 PM)
but blogosphere.us isn't can't really
be rated as spam can it?
by kohlehydrat (7/23/03, 8:08 PM)
More referrer spam www.webfrost.com
by Irene (7/23/03, 7:55 PM)
How to log skin names
I accessed to console?? Hi, I would like to know...
by winson (7/23/03, 4:12 PM)

Click here to get an XML version of this weblog.

Made with Antville
powered by
Helma Object Publisher