3 ms·
Instead of providing a temporary password, can't that service just give a user the session information that is sent to the server via cookies?
by hadcomplained 6y ago
Instead of providing a temporary password, can't that service just give a user the session information that is sent to the server via cookies?
- foobar_ 6y agoWell that is clever. Well lets see if it works ... I created this user overlookedscrum with a weak enough password, but you don't know it so you can't reset it. This is the cookie ~ key: user value: overlookedscrum&DtTI0rbgf7YKKL0Xgy65I4cJFAi962sH I tried it with two different browsers. It seems I can login freely, but can you ? I'll say ping below.
- overlookedscrum 6y agoping.
- overlookedscrum 6y agowell people seem to have flagged my previous message but it does work from a different ip address as well in this message. ping. need to see if this method can work with other apps like twitter. is this a security hole ? not sure .... this is basically the opposite of session hijacking because i'm just sharing my session and the password can't be changed. https://en.wikipedia.org/wiki/Session_hijacking https://en.wikipedia.org/wiki/Session_hijacking > Some services make secondary checks against the identity of the user. For instance, a web server could check with each request made that the IP address of the user matched the one last used during that session. This does not prevent attacks by somebody who shares the same IP address, however, and could be frustrating for users whose IP address is liable to change during a browsing session. would welcome anyone else to try.
- overlookedscrum 6y agoWorks for me, from some airvpn IP