Outline ·
[ Standard ] ·
Linear+
Queries can the mod/admin view our browser cookies?, just curious only
|
SUSdattebayo
|
Jan 16 2007, 07:18 PM, updated 19y ago
|
|
after we log in to LYN server, our browser has to send a cookie file to the server, in order to load our usual setting, and our last activity...
but a thing comes to my wonder, can the mods view that cookie file? it can be viewed by typing: javascript:alert("Cookies: "+document.cookie) at the address bar, and it contains member_id, unique_id ..
|
|
|
|
|
|
nexus-
|
Jan 16 2007, 07:22 PM
|
The intrepid coward
|
No, moderators will not be able to snoop your cookies. They are used for login, some user preferences and Google analytics.
|
|
|
|
|
|
SUSdattebayo
|
Jan 16 2007, 07:24 PM
|
|
then how about those higher rank such as staff and admins? or is that mean No One Human would have access to cookies?
|
|
|
|
|
|
wKkaY
|
Jan 16 2007, 07:31 PM
|
misutā supākoru
|
nexus-, se7en, and I have access to the webserver and we can view it if we really wanted to. Any party that controls the path between you and the webserver can view it too, if they really wanted to.
Except for these extraordinary cases, only the forum software, google analytics, and possibly the javascript ads will be mucking around with your cookies.
|
|
|
|
|
|
SUSMike3300
|
Jan 16 2007, 10:09 PM
|
|
I don't know wht but with Firefox and viewing forum.lowyat.net, my system will lag for a moment and the page is showing "static.lowyat.net"
It is so irritating and how to fix it? Something wrong with the site?
|
|
|
|
|
|
wKkaY
|
Jan 16 2007, 10:27 PM
|
misutā supākoru
|
static.lowyat.net should be fast. It's likely to be the ads, some of which are sourced from external servers.
|
|
|
|
|
|
deric88
|
Jan 16 2007, 10:55 PM
|
|
cookies i think can view..... the password not inside rite? password if i not mistaken nobody maybe except ipb developers can view, encrypted until admin also cannot view i think
|
|
|
|
|
|
wKkaY
|
Jan 17 2007, 06:25 AM
|
misutā supākoru
|
The cookie stores a hashed version of the password. Erm but it's not as if we need it anyway if we wanted to look into your personal stuff. We're not a bank with multiple layers of authorization and auditing - we're just a simple forum. This something you have to come to grip with, with most smaller websites. You can either put faith in the admins' professionalism, or you could be.. PARANOID  And although that password cookie is hashed, when you login it's sent in the clear. It's trivial to capture the password it at that login point, simply by saving the user/password fields of the form. It's also trivial for a third party to perform a replay attack with your cookie if he manages to get hold of it.
|
|
|
|
|
|
kanojo
|
Jan 19 2007, 03:10 PM
|
New Member
|
is it used to check whether an ID is a multiple of another existing ID?
|
|
|
|
|
|
wKkaY
|
Jan 19 2007, 03:18 PM
|
misutā supākoru
|
Yups, it's one of the instruments used.
|
|
|
|
|
|
tan_pang
|
Jan 19 2007, 03:37 PM
|
|
so, it mean the password can be seen if admin want to?? how about the PM??
|
|
|
|
|
|
wKkaY
|
Jan 19 2007, 03:42 PM
|
misutā supākoru
|
Your question has been answered in post #8.
|
|
|
|
|
|
sHawTY
|
Jan 19 2007, 05:20 PM
|
|
QUOTE(wKkaY @ Jan 16 2007, 07:31 PM) nexus-, se7en, and I have access to the webserver and we can view it if we really wanted to. Any party that controls the path between you and the webserver can view it too, if they really wanted to. What about RBR? He's one of the admin too, no? Sorry, just passing by only, and see this as an interesting topic...
|
|
|
|
|
|
[W]HIT3_@NG3L
|
Jan 20 2007, 02:19 PM
|
|
QUOTE(sHawTY @ Jan 19 2007, 05:20 PM) What about RBR? He's one of the admin too, no? Sorry, just passing by only, and see this as an interesting topic...  RBR is also one of the forum admin i guess wkkay forgot bout him his going to be mad
|
|
|
|
|
|
wKkaY
|
Jan 20 2007, 03:44 PM
|
misutā supākoru
|
RBR's a forum admin too but he handles the general administrative stuff. His expertise lies not in coding or server administration, but elsewhere. So, RBR no touchy touchy the web and DB servers, or we'll spanky spanky him
|
|
|
|
|
|
silverhawk
|
Jan 20 2007, 11:14 PM
|
Eyes on Target
|
The people who can access the web server can easily read any of the data you send/receive. That includes your passwords, private messages, browsing habits etc. The thing is, the admins normally have better things to do than to sniff through your private information. Nothing you use on the internet is ever truly private unless you own the entire infrastructure. Streamyx, hotmail, gmail, google etc have loads of data on you too. So those of you who are paranoid, you might want to stop using the internet
|
|
|
|
|