16
Quote:
m0nty wrote:
now u know why i claimed autologins to be not 100% secure, and that an exception oughta be included in it to stop admins being able to use autologin at all.
Sorry, I think that what you are saying is (partly) incorrect. Mith is _not_ saying that autologin is insecure (it might, but he is not telling it) but that the combination of the hole in the XML-RPC interface, wich will result in being able to obtain the md5 hash of your password, and the autologin hack will make your XOOPS installation insecure...
And since autologin hacks mostly (if not all) safe the hash of your password and username in a cookie, the hackers will be able to login by simply modifying a cookie.
Correct me if I'm wrong.
Oracle: I'd ask you to sit down, but, you're not going to anyway. And don't worry about the vase.
Neo: What vase?
[Neo turns to look for a vase, and as he does, he knocks over a vase of flowers, which shatters on the floor.]
Oracle: That vase.
Neo:...