Are You Having Login Probs?

Posted on

Administrator Since: Apr 03, 2002

A small handful of people are reporting random logouts.

I recently discovered a hole in HRC authentication that would easily allow somebody to hijack somebody's profile. I have plugged that hole.

If it's happening some info would help to assist me in finding the problem.

- If it's different between logging in as a "remember me" log in or just a typical session login.
- What pages, if it's pridictable, that it happens on
- What cookies HRC currently has on your system, there should be two. "u_id" being your record ID and "challenge" being an encrypted character string to authenticate with.

If it is happening, one way to try and fix it would be to delete all the cookies on your system and login and see if it continues to happen.

Thanks for any help with this.

[ Back to Top ]


Member
Since: Jul 02, 2003


Jul 09, 2004 02:55 pm

Yep I'm getting logged out quite often. I always login with "remember me" checked.

I'm also running XP w/SP2 RC2 so that might have something to do with it, although it never happened prior to the change you made in login.

I've already tried deleting all my cookies.

Edit: Oh and whatever it's doing also makes some posts that I reply to disappear.:) I can search and find them again but they don't show up normally.

Administrator
Since: Apr 03, 2002


Jul 09, 2004 03:39 pm

Ahhhh SP2, OK, anyone else that has the problem, are you using SP2?

BIG mistake to put that in...whether or not it's the cause of this is another issue.

Hey, did you happen to respond to Walt posting about a song a couple days back?

Member
Since: Jul 02, 2003


Jul 09, 2004 03:44 pm

SP2 has been flawless, haven't had a single issue it with it.

Yep I had replied to Walts as well, but it showed up under a search, and I've seen it since recently.

Dan

Prince CZAR-ming
Member
Since: Apr 08, 2004


Jul 09, 2004 03:45 pm

i've had a couple times i've had to login, checked the 'remember me' both times. I figured it was due to running ad-aware every couple of days.

xp pro ver 2002, SP1
ms ie ver 6

Administrator
Since: Apr 03, 2002


Jul 09, 2004 03:47 pm

a couple of time I am not worried about cuz I had to change the login scheme a couple of times. If it happens today, then there is an issue.

SP2 is not flawless, there have been repeated warnings in tech magazines to be careful. The common home user may not be affected, but there ARE problems. NEVER use anything with "beta" or "RC" in the names from Microsoft...just a bad idea.

Well, off to catch the bus.

Cone Poker
Member
Since: Apr 07, 2002


Jul 09, 2004 05:30 pm

I was having login problems last night. Win XP Home Mozilla Browser

Administrator
Since: Apr 03, 2002


Jul 09, 2004 06:09 pm

OK, the login issues, and the missing post issues are related it appears, I think some of the missing posts should be back, altho reply counts and dates may not be accurate...

Administrator
Since: Apr 03, 2002


Jul 09, 2004 06:12 pm

Actually, I take that back, the lost posts are not back, they are in the database, but it would take me a while to find all the owners of each post, and it's only about 4-5 topics based on my queries of the database...so I may not take the time to get them back, keep close tabs please if you see it happen again.

Member
Since: Jul 02, 2003


Jul 09, 2004 08:00 pm

So far so good hear, no more auto logouts, fingers crossed. :)

Dan

Member
Since: Jan 18, 2003


Jul 09, 2004 08:20 pm

yeah it happened to me a few times on firefox, XP


Administrator
Since: Apr 03, 2002


Jul 10, 2004 05:11 am

www.mozilla.org/security/shell.html

Mozilla, Thunderbird and Firefox users may be interested in this security issue.

Member
Since: Jan 18, 2003


Jul 10, 2004 08:41 am

re-installed. aye, thanks.

darn it coco, i'm slowly becoming scottish.

Hello!
Member
Since: Jan 12, 2004


Jul 10, 2004 09:29 am

Hehe LOL!

Tis infectious for sure...look at me - I do it every day :-)

Still it's better than all the "yeeeeeeeehaaaaww's" I've been doin lately!

This problem seems to have rectified itself for me by the way - I had it a good 4 or 5 times but not since yesterday.

Ta.

Coco.

Administrator
Since: Apr 03, 2002


Jul 10, 2004 09:43 am

Good glad to hear it. Should there be any more issues, just let me know. When a guy has to edit something as major as the login authentication scheme, which is used on every page, with every visitor, the littlest problem can sometimes be huge...but it was a risk Ihad no choice but to take. And since most of the HRC development I kind do "on the fly" so to speak, things can get ugly now and then...

HRC doesn't really have the most professional live and development environments :-)

Hello!
Member
Since: Jan 12, 2004


Jul 10, 2004 09:49 am

As a webmaster for my own football site and various others, may I say what a good job you do keepin on top of this site and keepin it ship shape.

Many folks dont understand the time/effort/cost that goes into websites - so..well done DB and long LONG may it continue.

Coco.

Administrator
Since: Apr 03, 2002


Jul 10, 2004 10:02 am

Thanks Coco :-)

I'm Roscoooo P. Coltrane
Member
Since: Apr 12, 2003


Jul 10, 2004 11:41 am

I've been having logout problem too..as you might remember dB. Also, I have post problems; kinda like what olddog discribed about the post disappearing. When I click on a link, sometimes it will take me to another link. Like when I clicked on this one it took me to a post from 2001. Just thought it might be good to tell you.

I'm not sure what SP2 is but if you tell me I'll check it out.

I'm with coco..I think you do a great job on this site too! There's something that makes you feel like your home when your on here.

let's all have a community hug!(big warm smile)

Administrator
Since: Apr 03, 2002


Jul 10, 2004 02:28 pm

SP2 is the next service pack coming from Microsoft for Windows XP. It is still in beta right now.

Have you had problems today? Or are you referencing the former problems you experienced that we spoke of privately?

Oh, and Coco (as well as anyone else that uses my COntent Manager script available scripts.dbmasters.net which some others may I am not aware of) you should go to the scripts site and see the next generation CMS in development ;-) The next version is gonna ROCK!

I'm Roscoooo P. Coltrane
Member
Since: Apr 12, 2003


Jul 11, 2004 02:08 am

I'm still having some problems but not the logout issue we discussed. What happens is..when I click on: recently active threads and then go to click one of the posts, it then takes me to a post from 2002.(sorry, said before it was 2001)But if I click on message forums, then the subject forum like-Talkin' Smack, then click on the post...I can access one of the posts with no problem.

I hope I'm making sense. I don't really know any tech way to put it. Hope this helps.

Take it easy dB

Administrator
Since: Apr 03, 2002


Jul 11, 2004 06:02 am

Log out, delete all you cookies, at least all of them from HRC, and log back in, for about an hour a few days ago there was a cookie being set that interfered with some id's being passed around, and created that sort of a problem, odds are that cookie is still on your system.

I'm Roscoooo P. Coltrane
Member
Since: Apr 12, 2003


Jul 12, 2004 12:24 pm

Just wanted to say thanks dB. I done everything you said...no problems of any kind. Take it easy Bro!

Administrator
Since: Apr 03, 2002


Jul 12, 2004 12:30 pm

Awesome, glad to here it! Thanks for letting me know.

Related Forum Topics:



If you would like to participate in the forum discussions, feel free to register for your free membership.