ASP Free Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsOtherASP Free Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old October 1st, 2007, 09:06 PM
hantz85's Avatar
hantz85 hantz85 is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Sep 2007
Posts: 189 hantz85 Negative: is most likely a SPAMMER and a traitor to the cause. 
Time spent in forums: 1 Day 7 h 24 m 15 sec
Reputation Power: 0
Exclamation Discussion - Don'T Move!!!! CSI ASP!!

even if you will use several Sessions on your page...and even if the will be encrypted...
and even if you will pass a hidden variable by poss...
YOU WON'T B SAFE

sessions-
Code:
Session("sd233asd2334asdf342sdf")="sdsdsd343fsd34234"

cause sessions looks at you your ip...and if you will get out from your page some one can mask his ip and enter the page you left with your ip...and the page will think that he is you and will let him do everything he wants.

post hidden variable-
Code:
<input type="hidden" name="rwerfsrf3434" value="ewrwerwf3343">

you can see it on html...this is not a problem even to a bot , to copy those variables and to via post to enter some page..

what can we do?

Reply With Quote
  #2  
Old October 1st, 2007, 10:48 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 23 h 57 m 26 sec
Reputation Power: 181
Fantasy threads belong in the lounge, not the asp forum, and since the post is full of erroroneous information, it's moved. And besides the topic title annoyed me.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #3  
Old October 2nd, 2007, 04:22 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,932 Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 12 h 17 m 53 sec
Reputation Power: 2002
sorry hantz, but what you said is far from being true.
no idea where you learned this, you probably misread something.
if you can come with proof to what you say, be my guest.

Reply With Quote
  #4  
Old October 2nd, 2007, 05:14 AM
hantz85's Avatar
hantz85 hantz85 is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Sep 2007
Posts: 189 hantz85 Negative: is most likely a SPAMMER and a traitor to the cause. 
Time spent in forums: 1 Day 7 h 24 m 15 sec
Reputation Power: 0
people are you for real??

what is not true??
man...i can't believe u deleted the topic because you do not believe or because you afraid the law??
because that's exacltly how you hack...
that's like "man in the middle" but much more simple...
you just need to mask your ip to some users ...that's easier than stilling cookies...

people i see you are great in ASP but do not attached to the hacking world...and that's kind of strange...

Reply With Quote
  #5  
Old October 2nd, 2007, 05:46 AM
richyrich's Avatar
richyrich richyrich is offline
Contributing User
ASP Free Specialist (4000 - 4499 posts)
 
Join Date: Jun 2004
Location: Somewhere only we know...
Posts: 4,198 richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)  Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 2 Months 1 Week 1 Day 23 h 27 m 42 sec
Reputation Power: 1227
The topic has not been deleted, it has been moved.

Quote:
Originally Posted by hantz85
what is not true??

I believe they are referring to this statement:-
Quote:
Originally Posted by hantz85
cause sessions looks at you your ip...and if you will get out from your page some one can mask his ip and enter the page you left with your ip...and the page will think that he is you and will let him do everything he wants.

post hidden variable-

Code:
<input type="hidden" name="rwerfsrf3434" value="ewrwerwf3343">

you can see it on html...this is not a problem even to a bot , to copy those variables and to via post to enter some page..

A session does not store your IP address in the HTML code of a page or use hidden form elements to store data, which I believe is what you are suggesting. Not quite sure what relevance the code you posted has.

I don't think we understand the point you're trying to make. That you can see hidden form elements in the HTML source? That sessions create hidden form elements for you? That sessions store your IP address in the HTML code?
__________________
Policy Check

I'd rather have a full bottle in front of me, than a full frontal lobotomy...

Last edited by richyrich : October 2nd, 2007 at 05:50 AM.

Reply With Quote
  #6  
Old October 2nd, 2007, 05:47 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,932 Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 12 h 17 m 53 sec
Reputation Power: 2002
the topic is not deleted, it was moved to the Lounge forum.

if you're so smart, please prove your claims otherwise
don't assume what we know and what we don't know.

if I now have your IP, nothing will happen unless the code
itself is using the IP as the key - not good idea.
I won't have your cookies by having your IP.

Reply With Quote
  #7  
Old October 2nd, 2007, 06:35 AM
hantz85's Avatar
hantz85 hantz85 is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Sep 2007
Posts: 189 hantz85 Negative: is most likely a SPAMMER and a traitor to the cause. 
Time spent in forums: 1 Day 7 h 24 m 15 sec
Reputation Power: 0
Post i asked a question and got unbelievers...

it's like asking
"where is my car?"
and to get answer-
"you don't have a car! go away"

i won't write more about this cause i see no one know or no one want to share...
than it's my last post and it's goes like this-

you can test it in many ways-
when you getting sessions as security validation
the sessions look at your ip...and when you will close your browser in that moment some one can mask his ip to yours and to open the same page you just closed and the server will think that that is you...
that you just closed and open again the window and won't ask for validation again.

Reply With Quote
  #8  
Old October 2nd, 2007, 06:40 AM
jmurrayhead jmurrayhead is offline
Moderator
ASP Free God 17th Plane (13000 - 13499 posts)
 
Join Date: Feb 2004
Location: Reston, VA, USA
Posts: 13,091 jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)  Folding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced Folder
Time spent in forums: 3 Months 1 Week 11 h 23 m 46 sec
Reputation Power: 1580
ummm....no
__________________
jmurrayhead

Did I help you out? Make me popular by clicking the icon!

New Members:Proper way to post a question

Powered by ASP.Net

Reply With Quote
  #9  
Old October 2nd, 2007, 06:51 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,932 Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 12 h 17 m 53 sec
Reputation Power: 2002
do whatever you wish.
session is based on something known as Session ID.
it's not IP.
the Session ID is being stored as memory-only cookie
on the browser and that's what is used to identify the
browser.

Reply With Quote
  #10  
Old October 2nd, 2007, 07:12 AM
richyrich's Avatar
richyrich richyrich is offline
Contributing User
ASP Free Specialist (4000 - 4499 posts)
 
Join Date: Jun 2004
Location: Somewhere only we know...
Posts: 4,198 richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)richyrich User rank is General 4th Grade (Above 100000 Reputation Level)  Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1Folding Points: 129148 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 2 Months 1 Week 1 Day 23 h 27 m 42 sec
Reputation Power: 1227
I'm unsure if you are asking a question or making a statement?

If you're asking can someone access a secure account by masking your IP address and then trying to logon to the site the exact moment you leave the site, then No. See the reply from Shadow Wizard above. If you are using IP to validate users on your own site then I suggest you change this.

No-one is trying to be difficult. You have made a technical statement that everyone on here disagrees with. If you know something that we don't, perhaps you could post an example of how/where you have achieved or read this?

Hope that makes it clearer.

Reply With Quote
  #11  
Old October 2nd, 2007, 07:18 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,932 Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1Folding Points: 391471 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 12 h 17 m 53 sec
Reputation Power: 2002
there is that security breach in Gmail that allow hackers to
steal user accounts while browsing their emails - do you
mean such stuff, hantz?

even so, this is problem with their code and got nothing to
do with the system.

Reply With Quote
Reply

Viewing: