|
Re: forum security question [message #38991 is a reply to message #38975] |
Wed, 12 September 2007 18:32 |
Ilia
Messages: 13241 Registered: January 2002
Karma: 0
|
Senior Member Administrator Core Developer |
|
|
The forum only allows one active cookie per user, so if the admin is using the forum the old cookies/sessions will automatically be made invalid. The IP validation is unreliable because some ISPs like AOL change their user's IP all of the time.
Storing the password inside the cookie is very dangerous, since the hacker can simply steal it from there.
FUDforum Core Developer
|
|
|
|
|
|
|