Simple way to bypass the login?

Need help? Post your questions here.

Moderator: moderators

Simple way to bypass the login?

Postby manybuddhas » Thu May 28, 2009 8:55 pm

Entering the address of the Subsonic service on my Web server, which let's say is at http://66.185.19.125:8083/, takes me directly to the index rather than the log-in page, and provides access to all the functions in Subsonic.

If you remove the arguments after the http address: /login.view;jsessionid=qkzqn8cqqcc? you can just enter the index without having to log in.

I changed the admin password as described, but still this simple bypass is available. What am I missing?[/code]
manybuddhas
 
Posts: 3
Joined: Thu May 28, 2009 8:47 pm

Postby kdid » Thu May 28, 2009 10:21 pm

Have you tried that from a webbrowser that never have been used on you site?

It could be you have saved the login info in a cookie in your browser and it is using that in that case.
-- kdid
kdid
 
Posts: 131
Joined: Tue Jan 02, 2007 11:17 am

Postby aphuey » Fri May 29, 2009 5:40 pm

Yeah - I bet if you clear your temp files, you will be forced to log in again...
aphuey
 
Posts: 102
Joined: Mon Nov 17, 2008 6:25 pm

Postby mixmaster » Fri May 29, 2009 6:34 pm

There is a checkbox on the login page that allows you to choose between remembering your login or not.
________
Last edited by mixmaster on Sun Mar 06, 2011 2:07 am, edited 1 time in total.
mixmaster
 
Posts: 121
Joined: Thu Nov 13, 2008 5:30 am

Postby manybuddhas » Sat May 30, 2009 12:29 am

Thanks all. It was just a cookie, apparently, since the problem did not show up on a computer that hadn't accessed the site before. :oops:
manybuddhas
 
Posts: 3
Joined: Thu May 28, 2009 8:47 pm

Postby bluetooth » Sat Jun 06, 2009 3:14 pm

paid Subsonic user
bluetooth
 
Posts: 198
Joined: Mon Aug 04, 2008 6:57 pm


Return to Help

Who is online

Users browsing this forum: No registered users and 22 guests