  • 2005/2/18 23:30

  • dasdan

  • Just popping in

  • Posts: 29

  • Since: 2005/1/22

Peak auto-login hack

Re: auto-login hacked files for XOOPS
This hack stores the password as an MD5 hash on the client, but this is vulnerable to dictionary attacks, and simple copying to another computer.
This hack is a potential security hole, don't enable it lightly.

I was thinking , client logs in, server creates a unique random ID and stores in DB, sends it back to the client and stores it in a cookie. Next page visit, server cheques unique ID, if match -> generates a New ID, else user needs to login again. (possible a hacked)

Re: auto-login
  • 2005/2/18 23:36

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24

errr i'm not quite sure what the question is here?

have u tried GiJoes auto login hack?

personally if you think about it, having any kind of autologin is going to reduce security compared to a system that doesn't..

Re: auto-login
  • 2005/2/19 2:20

  • ahnah

  • Just popping in

  • Posts: 9

  • Since: 2004/11/29

Well ...my user also request to have such feature, guess is the user needs .. so why not make it an option in the XOOPS core module ?

Re: auto-login
  • 2005/2/19 13:49

  • dasdan

  • Just popping in

  • Posts: 29

  • Since: 2005/1/22

The reason of my post..

I read the comments on the peak download site for the auto-login module.
I think it's not realy secure to store the users hashed password in a cookie on the client.

It would be more secure to store a random id.

enabeling auto-login will always decrease security, i agree,
but storing a hashed pass sounds dangerous, when you know it can be decripted.

Re: auto-login
  • 2005/2/19 15:09

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24

maybe a random key is a good idea if it can be implemented right..

or maybe a user could tie his computer name/id to the autologin cookie, that way a script could probably read the users computer name which could also be stored in the DB.. if the computer name of the user doesn't match the 1 stored in the DB then autologin will not function, but still would allow the user to login in a single session but not be autologged in, that way it would still allow users to login from another PC and if done on public computers there's no chance of them being auto logged in again.. of course the user should be able to change his computer id via a setting in control panel..


Who's Online

188 user(s) are online (148 user(s) are browsing Support Forums)

Members: 0

Guests: 188



Goal: $100.00
Due Date: Dec 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits