login security issue

Post general support questions here that do not specifically fall into the Linux or Windows categories.

Moderators: Developers, Moderators

Post Reply
ackmie
Posts: 5
Joined: Tue Mar 08, 2005 6:11 pm

login security issue

Post by ackmie »

Hi all,

Is anyone else having this issue:

If you login and access the graphs tab then take that link to another seperate pc that has had its cache cleared and paste the link into the web browser it will bring up the privilages that the user had and not require them to login. :o

Is there a patch to fix this issue??

Thanks
User avatar
rony
Developer/Forum Admin
Posts: 6022
Joined: Mon Nov 17, 2003 6:35 pm
Location: Michigan, USA
Contact:

Post by rony »

Do you have php configured to use cookies for sessions?

If not, then this is possible, because it will pass the session ID on the URL. This is not cacti's doing.
[size=117][i][b]Tony Roman[/b][/i][/size]
[size=84][i]Experience is what causes a person to make new mistakes instead of old ones.[/i][/size]
[size=84][i]There are only 3 way to complete a project: Good, Fast or Cheap, pick two.[/i][/size]
[size=84][i]With age comes wisdom, what you choose to do with it determines whether or not you are wise.[/i][/size]
ackmie
Posts: 5
Joined: Tue Mar 08, 2005 6:11 pm

Post by ackmie »

I have session cookies enabled in my php.ini file. As i have session.use_cookies set to 1 (as bellow).

session.use_cookies = 1

Any idea what else may be causing this?
User avatar
TheWitness
Developer
Posts: 17004
Joined: Tue May 14, 2002 5:08 pm
Location: MI, USA
Contact:

Post by TheWitness »

Guest user rights?

TheWitness
True understanding begins only when we realize how little we truly understand...

Life is an adventure, let yours begin with Cacti!

Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages


For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
Post Reply

Who is online

Users browsing this forum: No registered users and 3 guests