WTF - posting as someone else?

For discussions about security.
Post Reply
Message
Author
gabtech
Posts: 107
Joined: Sun 14 Apr 2013, 11:42

WTF - posting as someone else?

#1 Post by gabtech »

nic007 has suddenly become gabtech?????????????????????? Posting this before logging out as gabtech and trying to login as nic007

User avatar
nic007
Posts: 3408
Joined: Sun 13 Nov 2011, 12:31
Location: Cradle of Humankind

#2 Post by nic007 »

Was able to login and post as nic007. What the hell happened?

User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

#3 Post by Flash »

I don't understand. Slow down a bit and tell us exactly what happened.

User avatar
nic007
Posts: 3408
Joined: Sun 13 Nov 2011, 12:31
Location: Cradle of Humankind

#4 Post by nic007 »

I never logout myself after a session so am normally logged in when I return to the forum. Today I visited the site and replied to a post, I then noticed that I was logged in as gabtech and posting under that name. Logged out and successfully logged in with my nic007 login. How did my live nic007 login status change to gabtech?

User avatar
Burn_IT
Posts: 3650
Joined: Sat 12 Aug 2006, 19:25
Location: Tamworth UK

#5 Post by Burn_IT »

Someone used your PC???
"Just think of it as leaving early to avoid the rush" - T Pratchett

User avatar
nic007
Posts: 3408
Joined: Sun 13 Nov 2011, 12:31
Location: Cradle of Humankind

#6 Post by nic007 »

No. gabtech is a registered user of this forum who last posted on 23 September 2018 according to his profile.

quirkian2new
Posts: 152
Joined: Tue 06 Oct 2015, 14:10
Location: on the inter-planet train

#7 Post by quirkian2new »

i remember some of us had asked why murga linux is not https enabled.

whenever i want to post something, i usually type it in a word processor, login , copy and then paste it, and then logout.

User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

#8 Post by Flash »

That doesn't explain how nic007 got changed to gabtech. Maybe the forum software was just having a bad day.

ITSMERSH

#9 Post by ITSMERSH »

Flash wrote:That doesn't explain how nic007 got changed to gabtech. Maybe the forum software was just having a bad day.
This seems to happen sequentially when Guests are in Off-Topic-Forum. :wink: :lol:

User avatar
rockedge
Posts: 1864
Joined: Wed 11 Apr 2012, 13:32
Location: Connecticut, United States
Contact:

#10 Post by rockedge »

Maybe the forum software was just having a bad day.
That should never be a thing with program code all of a sudden.
This seems to happen sequentially when Guests are in Off-Topic-Forum
hey ITSMERSH what do you mean? I would like to repeat this and find out in the code why this is possible. It may be a session cookie problem. Can you explain your reason for this login transfer...

ITSMERSH

#11 Post by ITSMERSH »

I have watched multiple times Guests showing up in the Off-Topic-Forum when I was logged in and visiting this section (made at least two topics/posts about that issue some time ago).

Usually this section is invisible for members not being logged in (or is logged on the right saying?).

Checked right now: shows 1 Hidden (me) and 0 Guests.

I can't imagine this being be a cookie problem. :?

belham2
Posts: 1715
Joined: Mon 15 Aug 2016, 22:47

#12 Post by belham2 »

I think nic007 was drinking too much whiskey, that he was dreaming and/or talking about in another thread.

Ya gotta watch that hard stuff, it kicks like a mule at a certain point :wink:

User avatar
tallboy
Posts: 1760
Joined: Tue 21 Sep 2010, 21:56
Location: Drøbak, Norway

#13 Post by tallboy »

quirkian2new wrote:whenever i want to post something, i usually type it in a word processor, login , copy and then paste it, and then logout
That is a good practice, I have seen too many members in other forums, who are permanently logged in, I am sure there are some here too. :shock: I always log in for my daily dose, and close the browser when I log out, thus deleting all cookies and history. I have also made the startup script for my Palemoon to start with:

Code: Select all

rm -r /root/.cache/moonchild*
, the same with Thunderbird. They are not automatically emptied with a setting in prefs.
True freedom is a live Puppy on a multisession CD/DVD.

User avatar
nic007
Posts: 3408
Joined: Sun 13 Nov 2011, 12:31
Location: Cradle of Humankind

#14 Post by nic007 »

belham2 wrote:I think nic007 was drinking too much whiskey, that he was dreaming and/or talking about in another thread.

Ya gotta watch that hard stuff, it kicks like a mule at a certain point :wink:
Hey, watchit!!!

User avatar
Burn_IT
Posts: 3650
Joined: Sat 12 Aug 2006, 19:25
Location: Tamworth UK

#15 Post by Burn_IT »

He was making a Wry comment????
"Just think of it as leaving early to avoid the rush" - T Pratchett

User avatar
a_salty_dogg
Posts: 180
Joined: Sun 15 Dec 2013, 19:08

#16 Post by a_salty_dogg »

Burn_IT wrote:He was making a Wry comment????
:lol:

Took me a while to understand that comment but now I see it in Black & White and I'm not Grousing! :wink:

s243a
Posts: 2580
Joined: Tue 02 Sep 2014, 04:48
Contact:

#17 Post by s243a »

nic007 wrote:I never logout myself after a session so am normally logged in when I return to the forum. Today I visited the site and replied to a post, I then noticed that I was logged in as gabtech and posting under that name. Logged out and successfully logged in with my nic007 login. How did my live nic007 login status change to gabtech?
I don't completely understand this yet but I did find the following:
The attack consists of obtaining a valid session ID (e.g. by connecting to the application), inducing a user to authenticate himself with that session ID, and then hijacking the user-validated session by the knowledge of the used session ID. The attacker has to provide a legitimate Web application session ID and try to make the victim's browser use it.
https://www.owasp.org/index.php/Session_fixation

User avatar
nic007
Posts: 3408
Joined: Sun 13 Nov 2011, 12:31
Location: Cradle of Humankind

#18 Post by nic007 »

I wasn't asked to do anything as user. When I visited the forum I was magically logged in as gabtech instead of nic007

User avatar
fredx181
Posts: 4448
Joined: Wed 11 Dec 2013, 12:37
Location: holland

#19 Post by fredx181 »

nic007 wrote:I wasn't asked to do anything as user. When I visited the forum I was magically logged in as gabtech instead of nic007
This is really weird !!!, completely the other way around, in fact it looks like gabtech is the victim of being "hacked" (unintended, I believe you :wink: ) by you.
(if I understand well)

I wonder what gabtech thinks about it, but it looks like he/she is not around here anymore.

Fred

Post Reply