Search the database
Search forum topics
Search members
Search for trades
diablo2.io is supported by ads
diablo2.io is supported by ads
1 reply   2351 views
2

Description

Device:
Browser:
OS:

Steps to reproduce:

1. Create account
2. Get redirected to the front page
3. Notice sid is in the URL. This is not secure since I could copy and paste this link not knowing it's my session id. Someone could hijack my session.

Anything else to add:
5

Can be used to make Runewords:

7
Device:
Browser:
OS:

Steps to reproduce:

1. Create account
2. Get redirected to the front page
3. Notice sid is in the URL. This is not secure since I could copy and paste this link not knowing it's my session id. Someone could hijack my session.

Anything else to add:
Fixedby Teebling3 years agoGo to post
Auxis wrote: 3 years ago
3. Notice sid is in the URL. This is not secure since I could copy and paste this link not knowing it's my session id. Someone could hijack my session.
SIDs have been in phpBB topic urls for 20 years and more. If there was a security concern about this I think they would have changed it by then.
7
User avatar

Teebling 6688Admin

Europe PC
Auxis wrote: 3 years ago
3. Notice sid is in the URL. This is not secure since I could copy and paste this link not knowing it's my session id. Someone could hijack my session.
SIDs have been in phpBB topic urls for 20 years and more. If there was a security concern about this I think they would have changed it by then.
This post was marked as the fix.

9

Advertisment

Hide ads
999

Greetings stranger!

You don't appear to be logged in...

99

Who is online

Users browsing Bug Reports: No registered users and 4 guests.

No matches
 

 

 

 

Value:
Hide ads forever by supporting the site with a donation.

Greetings adblocker...

Warriv asks that you consider disabling your adblocker when using diablo2.io

Ad revenue helps keep the servers going and supports me, the site's creator :)

A one-time donation hides all ads, forever:
Make a donation