So I logged onto today from NC and checked the remember me button. Then when I got home I signed in again and I got the "Cookie hijacked message". It said to report it because it has never happened.
mwinter
Total posts: 4327
5/6/2007 1:47 AM
yay.. i'll check the database and see what it looks like :) lemme make sure i got the situation correct:
1) login on computer A with "remember me" checked 2) login on computer B with "remember me" not checked
or was it the same computer? if it's the same computer and you still have the cookie it'd be nice to see the contents. you can view it in Firefox pretty easily by going to preferences -> privacy -> show cookies.
mwinter
Total posts: 4327
5/6/2007 1:53 AM
one possibility is that my random number generation isn't random enough.. i'll have to look at how i'm making the keys.
Shawn
Total posts: 1367
5/6/2007 3:45 AM
I will have to check the cookie but it was the same computer both times. The first time the box was checked and the second the box may or may not have been checked. I was at a Comfort Inn on their internet service if that makes any difference
mwinter
Total posts: 4327
5/6/2007 4:29 AM
was it wireless? I took a look at the code and nothing's jumping out at me.. in which case it's possible that someone actually intercepted joor cookie. never expected that to happen :) if you can duplicate it then i'd be more inclined to think that it's a bug.
Whenever a hijacking occurs it clears out the database entry for that particular cookie's loginability so your account should be safe.
BadJohnny
Total posts: 26
6/13/2007 5:58 AM
I think something needs to be done about the current image situation (i.e. you have to type in that goofy name & password to see members only pics). It would be pretty easy to store all images in a binary field of a database; other fields could be used to store all sorts of useful metadata about each image but best of all we could access images using our normal login credentials.
Drew
Total posts: 5115
6/13/2007 7:03 AM
i kinda like the dual and independent security
Shawn
Total posts: 1367
7/8/2007 5:08 PM
I would like there to be a upload file option. Also I am not sure if this had already been suggested but a picture archive would be very cool. Maybe even some space for awesome Club409 pictures of the past.