Antville Project

cookies and security-issues

to fix a security-hole in antville we had to change the cookie-creation and -handling three days ago. as some of you already noticed the "remember me"-feature seems to work differently. this is because of our fix, and unfortunatly it seems to be the only possible solution:

from now on the "remember me"-feature will only work for those who have a static ip-address, for most modem/adsl-users it won't resp. just as long as they they keep their ip-address. this is because we're now using the client-ip as part of the key that is stored in one of the cookies used by the "remember me"-feature.

those who have antville installed somewhere should update their installations (the fix is already in cvs, in both the main- and the need_for_speed-branch). to give you a brief description: before it was possible for a weblog-owner to retrieve the "remember-me"-cookies of visitors and use them to log in as a differnt user. this has never happened (afaik), but of course we had to fix the hole.

sorry for the inconvenience.

comment    

 
alex63, November 22, 2002 at 1:08:47 AM CET

Re: cookies and security-issues

in my case the remember me works in the office but doesn't work at home. can i make it work at home by clearing the cookies at work?

link  

 
alex63, November 22, 2002 at 10:12:29 PM CET

Re: Re: cookies and security-issues

i just lost a post at home because of this annoying remember me thing. it asks me to log in and presents me an empty post afterwards. this reminds me (in a bad way) very much of my old blogger times. actually at work today (worldcom isdn permanent connection i think) i also had to log in. that really is a nuisance.

link  


... comment
 
mutant, November 22, 2002 at 2:39:49 AM CET

breaks comfortability

for me totally. i'm working with a static ip the whole day on an ibook. when i get back home and switch to my adsl environment, i have lotsa problems. makes antville almost unusable. more on this tomorrow, getting tired now.

[update]:(in german, sorry for the inconvinience)

ich bin mir ziemlich sicher, das diese loesung eines vermeintlichen problems der antville-community das genick brechen wird. kaum einer hat eine feste ip und wenn man zwischen environments(wie uni +zuhause) switched, ist man eh gefi**t. staendig cookies loeschen und browser neu starten etc, das macht kein spass. denkt da bitte noch mal drueber nach. siehe auch zb beim seewolf.

link  


... comment


The Antville Server Fund has been a great success. Thanks to everybody who contributed!
online for 8549 Days
last updated: 1/4/11, 10:22 AM
status
Youre not logged in ... Login
menu
November 2024
SunMonTueWedThuFriSat
12
3456789
10111213141516
17181920212223
24252627282930
July
recent
zfuture's house here is zfuture's
house
by zfuture (7/31/03, 2:59 AM)
i understand your concerns however,
i hardly can think of a solution. certainly, if the...
by tobi (7/29/03, 9:47 AM)
Found several more similar sites
listed This is getting to be quite a concern to...
by cobalt123 (7/27/03, 7:56 PM)
Second Post Alert on Referrer
bug livecatz I put this into "help" and now here:...
by cobalt123 (7/26/03, 7:14 PM)
well it's not easy to
find from here, anyway. think we should include a link,...
by tobi (7/24/03, 11:25 AM)
So finally I found
the helma Bugzilla - stupid me.
by mdornseif (7/24/03, 10:28 AM)
clock not that it's particularly
earthshattering but the antclock is running slow by about 15...
by kohlehydrat (7/23/03, 8:25 PM)
but blogosphere.us isn't can't really
be rated as spam can it?
by kohlehydrat (7/23/03, 8:08 PM)
More referrer spam www.webfrost.com
by Irene (7/23/03, 7:55 PM)
How to log skin names
I accessed to console?? Hi, I would like to know...
by winson (7/23/03, 4:12 PM)

Click here to get an XML version of this weblog.

Made with Antville
powered by
Helma Object Publisher