Jump to content

Security question

Featured Replies

Posted

When we access the control pannel of the board the url to it is kept in the browser and it allows you to gain access to the administrative section even after the administrator is logged out. Was something done with this new version to make the link expire so if someone uses the computer they cannot get into the administrative section of the board by clicking on the link that's in the browser historic?

It expires for me.
I have left the admin window open for a few hours and when I clicked on a link while in it I was redirected back to the log on page.

It depends what you have for all the session settings etc.

it's related then to the time you set for a login session to expire. in my opinion the administrative control pannel link should expire in the moment the administrator logs out.

Session expires after two hours of no use [or something like that].

There is now a log out link in the acp, if you click it, logging out, then try to access the ACP using the session ID from before you logged out, you get an error

it's good to know. it avoids someone to hijack our session and crack our forum.

Firstly, unless you modify IPB, the ACP session is tied to your IP address. So no one can hijack it, unless they have the same IP address.

Secondly, it auto-disables the session after 15 minutes of inactivity.

And thirdly, yes, there is now a manual log out link which I would recommend clicking on if clearing the session is a top concern. :)

Archived

This topic is now archived and is closed to further replies.

Recently Browsing 0

  • No registered users viewing this page.