3 ms·
I wonder if there can be a public version of this by sharing passwords openly but in a twisted way. 1. Create an account. 2. To know the password, you visit a
by foobar_ 6y ago
I wonder if there can be a public version of this by sharing passwords openly but in a twisted way.
1. Create an account.
2. To know the password, you visit a service that gives you the password.
3. The service changes the password immediately in 10 seconds before which you login.
4. You can now post stuff with the account but can't change the password allowing another user to chime in.
Now the service basically needs to not allow another user to login in 10 seconds. If the website doesn't allow multiple users to login then there needs to be an etiquette of one user at a time, although you can kick off the user after a definite amount of time if the website allows logout from all sessions.
- hadcomplained 6y agoInstead of providing a temporary password, can't that service just give a user the session information that is sent to the server via cookies?
- foobar_ 6y agoWell that is clever. Well lets see if it works ... I created this user overlookedscrum with a weak enough password, but you don't know it so you can't reset it. This is the cookie ~ key: user value: overlookedscrum&DtTI0rbgf7YKKL0Xgy65I4cJFAi962sH I tried it with two different browsers. It seems I can login freely, but can you ? I'll say ping below.
- overlookedscrum 6y agoping.
- overlookedscrum 6y agowell people seem to have flagged my previous message but it does work from a different ip address as well in this message. ping. need to see if this method can work with other apps like twitter. is this a security hole ? not sure .... this is basically the opposite of session hijacking because i'm just sharing my session and the password can't be changed. https://en.wikipedia.org/wiki/Session_hijacking https://en.wikipedia.org/wiki/Session_hijacking > Some services make secondary checks against the identity of the user. For instance, a web server could check with each request made that the IP address of the user matched the one last used during that session. This does not prevent attacks by somebody who shares the same IP address, however, and could be frustrating for users whose IP address is liable to change during a browsing session. would welcome anyone else to try.
- overlookedscrum 6y agoWorks for me, from some airvpn IP