Post shows up as different users Hitskin_logo Hitskin.com

This is a Hitskin.com skin preview
Install the skinReturn to the skin page

The forum of the forums
Would you like to react to this message? Create an account in a few clicks or log in to continue.
2 posters

    Post shows up as different users

    Al Bundy
    Al Bundy
    Forumember


    Male Posts : 39
    Reputation : 0
    Language : English

    Post shows up as different users Empty Post shows up as different users

    Post by Al Bundy June 3rd 2008, 3:15 pm

    I was reviewing posts and noticed one that should be responded to by a specific individual (in this case a mod) so I just copied and pasted the link into an e-mail to that user.

    They clicked the link, and replied to the post. However, the reply shows it is from me and not that user. They were never asked to log in, so it looks like the link I sent also had my security info embedded in it.

    Can this be fixed.
    avatar
    zakir321
    New Member


    Posts : 0
    Reputation : 2
    Language : english

    Post shows up as different users Empty Re: Post shows up as different users

    Post by zakir321 June 3rd 2008, 4:07 pm

    Don't provide links that contain a "sid=" part. For more info, please read this topic:

    https://help.forumotion.com/frequently-asked-questions-f5/internet-security-on-you-forum-habits-to-be-avoided-t51.htm
    Al Bundy
    Al Bundy
    Forumember


    Male Posts : 39
    Reputation : 0
    Language : English

    Post shows up as different users Empty Re: Post shows up as different users

    Post by Al Bundy June 3rd 2008, 10:51 pm

    Thanks for the tip, but isn't this a severe security risk that should be fixed?
    Please tell me this is being looked at.
    avatar
    zakir321
    New Member


    Posts : 0
    Reputation : 2
    Language : english

    Post shows up as different users Empty Re: Post shows up as different users

    Post by zakir321 June 4th 2008, 3:28 pm

    Well, not sure if it's necessary. In my time being here, I've never noticed another case where someone was able to login into another account through a "sid"-link. So you can be sure this is happening very rarely and it's avoidable; do you share the same network or something with this user?
    Al Bundy
    Al Bundy
    Forumember


    Male Posts : 39
    Reputation : 0
    Language : English

    Post shows up as different users Empty Re: Post shows up as different users

    Post by Al Bundy September 8th 2008, 4:25 pm

    As this forum I created is strictly for use by our company's employees, the vast majority of the users are using the same LAN, hitting the board with the same ip address.

    Am I the only one here concerned with this security hole?
    How come this doesn't happen with standalone phpBB boards? Can't this be fixed?