vtiger Forum Index vtiger
The Honest Open Source CRM
 

login security
Click here to go to the original topic

 
       vtiger Forum Index -> Usability & Themes - 4.x
Previous topic :: Next topic  
Author Message
ftc



Joined: 26 Apr 2006
Posts: 24
Location: Perth, Australia

Posted: Wed Apr 26, 2006 5:14 am    Post subject: login security  

Hi there....just exploring the wonders of vtiger installed at my site. Well, by pure ignorance, I have found out that by closing the application by the windows x instead of the proper "Logout" , the next user using the vtiger system bypass the login screen and straight to the main menu (with all the information left by the previous user). Any idea? or just the bad habit of not logging out properly???
Back to top  
johnwong
Guest





Posted: Fri Apr 28, 2006 12:13 am    Post subject: login security  

Try using .htaccess
You will need to secure your system. This should not be happening.
Back to top  
kenlyle
Guest


Joined: 16 Apr 2006
Posts: 108

Posted: Fri May 05, 2006 6:31 pm    Post subject: Re: login security  

I just verified this issue in 4.2.4rC2.

I close the tab in Firefox, then open a new tab, and enter the vTiger URL, and I get right in without having to authorize.

Probably, there is a cookie that is living too long. This seems like a serious issue in any environment that cares at all about data security. Even if the users are legitimate employees, sometimes they are not supposed to see each others' data.

I found that if I delete both the ck_login_id associated with the vtiger directory and PHPSESSID associated with /, then the login requies me to authenticate.

Hopefully, one of the devs can jump in with a quick fix.

K
Back to top  
kenlyle
Guest


Joined: 16 Apr 2006
Posts: 108

Posted: Fri May 05, 2006 6:32 pm    Post subject: Re: login security  

I just verified this issue in 4.2.4rC2.

I close the tab in Firefox, then open a new tab, and enter the vTiger URL, and I get right in without having to authorize.

Probably, there is a cookie that is living too long. This seems like a serious issue in any environment that cares at all about data security. Even if the users are legitimate employees, sometimes they are not supposed to see each others' data.

I found that if I delete both the ck_login_id associated with the vtiger directory and PHPSESSID associated with /, then the login requies me to authenticate.

Hopefully, one of the devs can jump in with a quick fix.

K
Back to top  
 
       vtiger Forum Index -> Usability & Themes - 4.x
Page 1 of 1


Powered by phpBB Search Engine Indexer
Powered by phpBB 2.0.15 © 2001, 2002 phpBB Group