1
dejadingo
Session hijacked?
  • 2005/12/19 21:04

  • dejadingo

  • Just popping in

  • Posts: 71

  • Since: 2004/10/22


I'm still using XOOPS 2.0.9.3 (pressed for time at the moment) and Saturday I had two ContactUs emails that seem to have assumed my Webmaster user ID -- my email is in the From header on the primary email and the confirmation email was addressed to my webmaster user name and sent to my webmaster email!

This makes me very nervous. Is this a session hijack issue? I can't see anything in the code that might lead to this result.

Thanks.

2
dejadingo
Re: Session hijacked?
  • 2005/12/20 1:55

  • dejadingo

  • Just popping in

  • Posts: 71

  • Since: 2004/10/22


Sorry for the *bump* but ..
Can anyone help me with session issues?

- How could an anonymous user send a ContactUs message with my Webmaster user and email?
- Why are there multiple records with the same IP in the xoops_session table?

Thanks.

3
m0nty
Re: Session hijacked?
  • 2005/12/20 2:42

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24


have you got cache enabled for the contact us block? i know there was an old issue that if cache was enabled for contact us, and a webmaster had used it and sent a contact us.. then the page would be cached with his information..

but either way without seeing your site or the message headers we won't know anything.. i doubt it's a session hijack..

Login

Who's Online

298 user(s) are online (243 user(s) are browsing Support Forums)


Members: 0


Guests: 298


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits