Active Topics

 


Reply
Thread Tools
Jaffa's Avatar
Posts: 2,535 | Thanked: 6,681 times | Joined on Mar 2008 @ UK
#11
URL for raising this as a bug:

https://bugs.maemo.org/enter_bug.cgi....org%20Website
__________________
Andrew Flegg -- mailto:andrew@bleb.org | http://www.bleb.org
 

The Following 3 Users Say Thank You to Jaffa For This Useful Post:
giecsar's Avatar
Posts: 91 | Thanked: 34 times | Joined on Apr 2010 @ Italy
#12
Originally Posted by Jaffa View Post
Then can you please do one of:
  1. Attach it to a new bug report, including details of what you did to get there; the username you've logged on with and a series of screenshots showing each expanded menu entry.
  2. Crop it and re-attach.
I'm very sorry man, it's been a few days and when HellFlyer said that Reggie saw it and it's all ok I deleted the screenshot, I figured you either didn't really care or you knew about it..

Anyway my guess (just a hypothesis) is that Midgard has a serious flaw in that it checks the validity of the username and password independently. In other words, you can, in theory, log in with a user name from any valid account and a password from any other valid account. I'm saying this because basically what happened was I logged in with Safari but I only wrote my username and the browser filled in the password for me (must have been another password because I don't usually use Safari). I was then logged in as Technical GanXta instead of giecsar, as you can see from the screenshot (that text is actually readable).
__________________
Programmer, web designer/developer, abstract artist. Curently working on an experimental next-gen website, http://www.forum2point0.net
 
Posts: 540 | Thanked: 288 times | Joined on Sep 2009
#13
Originally Posted by giecsar View Post
Anyway my guess (just a hypothesis) is that Midgard has a serious flaw in that it checks the validity of the username and password independently. In other words, you can, in theory, log in with a user name from any valid account and a password from any other valid account.
Nope, though in this case authentication is done via pam from garage db so the postgres end might have issue, but read on.

Originally Posted by giecsar View Post
I'm saying this because basically what happened was I logged in with Safari but I only wrote my username and the browser filled in the password for me (must have been another password because I don't usually use Safari). I was then logged in as Technical GanXta instead of giecsar, as you can see from the screenshot (that text is actually readable)
More likely is that for reason you managed to somehow hit page that was cached for another user. I can't check this in detail now since I'm on a business trip but I emailed some people to look into it.
__________________
  • Live near Helsinki, Finland & interested in electronics ? Check this out.
  • Want anti-virus/firewall ? Read this (and follow the links, also: use the search, there are way too many threads asking the same questions over and over and over again).
  • I'm experimenting with BitCoins, if you want to tip me send some to: 1CAEy7PYptSasN67TiMYM74ELDVGZS6cCB
 
Reply


 
Forum Jump


All times are GMT. The time now is 12:59.