13
Quote:
tl wrote:
But, it also allows another person to log in using the same username five minutes after the initial user having logged in, so multiple logins are still possible. The hack only works in the initial 5 minutes.
I forgot to show some codes.
Of course, if nothing is done for five minutes or more after an user logs it in, it is taken care of to have logged out.
Naturally, it is possible to log in from another machines.
If the security of the site is very important, You may lengthen it more for a long time though I assumed the time of the time-out to be five minutes (300sec).
However, when a browser is closed without logging out by mistake, log in cannot be wholly done in that case during the long time.
Please adjust it properly according to the policy of the site.