Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Queries can the mod/admin view our browser cookies?, just curious only

views
     
SUSdattebayo
post Jan 16 2007, 07:18 PM, updated 19y ago

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


after we log in to LYN server, our browser has to send a cookie file to the server, in order to load our usual setting, and our last activity...

but a thing comes to my wonder, can the mods view that cookie file?
it can be viewed by typing: javascript:alert("Cookies: "+document.cookie) at the address bar, and it contains member_id, unique_id ..
nexus-
post Jan 16 2007, 07:22 PM

The intrepid coward
Group Icon
VIP
3,744 posts

Joined: Jan 2003
From: Sydney, Australia



No, moderators will not be able to snoop your cookies. They are used for login, some user preferences and Google analytics.
SUSdattebayo
post Jan 16 2007, 07:24 PM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


then how about those higher rank such as staff and admins?

or is that mean No One Human would have access to cookies? unsure.gif
wKkaY
post Jan 16 2007, 07:31 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
nexus-, se7en, and I have access to the webserver and we can view it if we really wanted to. Any party that controls the path between you and the webserver can view it too, if they really wanted to.

Except for these extraordinary cases, only the forum software, google analytics, and possibly the javascript ads will be mucking around with your cookies.
SUSMike3300
post Jan 16 2007, 10:09 PM

Look at all my stars!!
*******
Senior Member
6,866 posts

Joined: Feb 2005


I don't know wht but with Firefox and viewing forum.lowyat.net, my system will lag for a moment and the page is showing "static.lowyat.net"

It is so irritating and how to fix it? Something wrong with the site?
wKkaY
post Jan 16 2007, 10:27 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
static.lowyat.net should be fast. It's likely to be the ads, some of which are sourced from external servers.
deric88
post Jan 16 2007, 10:55 PM

Spam Ranking
******
Senior Member
1,464 posts

Joined: Dec 2004
cookies i think can view..... the password not inside rite?
password if i not mistaken nobody maybe except ipb developers can view, encrypted until admin also cannot view i think
wKkaY
post Jan 17 2007, 06:25 AM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
The cookie stores a hashed version of the password. Erm but it's not as if we need it anyway if we wanted to look into your personal stuff. We're not a bank with multiple layers of authorization and auditing - we're just a simple forum. This something you have to come to grip with, with most smaller websites. You can either put faith in the admins' professionalism, or you could be.. PARANOID shocking.gif

And although that password cookie is hashed, when you login it's sent in the clear. It's trivial to capture the password it at that login point, simply by saving the user/password fields of the form. It's also trivial for a third party to perform a replay attack with your cookie if he manages to get hold of it.
kanojo
post Jan 19 2007, 03:10 PM

New Member
*
Junior Member
25 posts

Joined: Jan 2007


is it used to check whether an ID is a multiple of another existing ID? unsure.gif
wKkaY
post Jan 19 2007, 03:18 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
Yups, it's one of the instruments used.
tan_pang
post Jan 19 2007, 03:37 PM

Look at all my stars!!
*******
Senior Member
3,110 posts

Joined: Jun 2005


so, it mean the password can be seen if admin want to??
how about the PM??
wKkaY
post Jan 19 2007, 03:42 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
Your question has been answered in post #8.
sHawTY
post Jan 19 2007, 05:20 PM

Frequent Reporter
********
All Stars
14,909 posts

Joined: Jul 2005

QUOTE(wKkaY @ Jan 16 2007, 07:31 PM)
nexus-, se7en, and I have access to the webserver and we can view it if we really wanted to. Any party that controls the path between you and the webserver can view it too, if they really wanted to.

*
What about RBR? blink.gif
He's one of the admin too, no? blink.gif

Sorry, just passing by only, and see this as an interesting topic... smile.gif
[W]HIT3_@NG3L
post Jan 20 2007, 02:19 PM

Look at all my stars!!
*******
Senior Member
2,104 posts

Joined: Nov 2004
QUOTE(sHawTY @ Jan 19 2007, 05:20 PM)
What about RBR? blink.gif
He's one of the admin too, no? blink.gif

Sorry, just passing by only, and see this as an interesting topic... smile.gif
*
RBR is also one of the forum admin
i guess wkkay forgot bout him
his going to be mad wink.gif
wKkaY
post Jan 20 2007, 03:44 PM

misutā supākoru
Group Icon
VIP
6,008 posts

Joined: Jan 2003
RBR's a forum admin too but he handles the general administrative stuff. His expertise lies not in coding or server administration, but elsewhere. So, RBR no touchy touchy the web and DB servers, or we'll spanky spanky him brows.gif
silverhawk
post Jan 20 2007, 11:14 PM

Eyes on Target
Group Icon
Elite
4,956 posts

Joined: Jan 2003


The people who can access the web server can easily read any of the data you send/receive. That includes your passwords, private messages, browsing habits etc.

The thing is, the admins normally have better things to do than to sniff through your private information. Nothing you use on the internet is ever truly private unless you own the entire infrastructure. Streamyx, hotmail, gmail, google etc have loads of data on you too.

So those of you who are paranoid, you might want to stop using the internet tongue.gif

 

Change to:
| Lo-Fi Version
0.0172sec    0.59    5 queries    GZIP Disabled
Time is now: 20th December 2025 - 08:56 PM