PEAK XOOPS - Re: Session Management in englishin japanese

Re: Session Management

List posts in the topic

raise it Re: Session Management

msg# 1.1.1.1
depth:
3
Previous post - Next post | Parent - No child | Posted on 2007/7/8 3:14 | Last modified
gigamaster  三等軍曹 From: Geneva, Switzerland  Posts: 94
Quote:
Since you are worried about security, the dual session records makes it possible for someone to hook into a Xoops system even though there has been a logout. I'm not sure of the specific cases, but I've been able to trigger the problem with some frequency. So peoples' concerns about not logging off are VERY VALID and IMPORTANT. There is a hole in the 2.0.16 version.

Yes, that's true - easy password cracking, phpmailer and sessions. But JMorris, David, Monty or Herko insist for long that "Xoops by Skalpa" was secure (even they're not programmers). At the same time they recommend "Protector"

Finally it seems that Nobunobu has worked on such issue on Legacy which i think emulates better "Xoops" than Xoops it-self. Well, to be honest, i didn't test the last release yet! But since XCL programmers have listen and consider to review such comments by the past, i'm quite sure they are prevent such issues.

Votes:0 Average:0.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!