Adult Webmaster Forum Adult Affiliates  
Go Back   Adult Webmaster Forum Adult Affiliates > WebmasterBooty.com > Lounge

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-26-2007, 02:47 AM
Junior Member
 
Join Date: Jun 2007
Posts: 1
Security flaw found in Orkut. Is it still safe to use?

A session management error has been found in Orkut. The error report is present at: http://lists.grok.org.uk/pipermail/f.../064143.htmlIs it still safe to use Orkut? Will you still use Orkut? What do you suggest?
Reply With Quote
  #2 (permalink)  
Old 06-26-2007, 02:48 AM
Junior Member
 
Join Date: Jun 2007
Posts: 1
I would and:Solutions:-1. The session associated with 'orkut_state' cookie must expire at the server side when the user logs out.2. The session associated with 'orkut_state' cookie must be disabled temporarily when a user fails authentication during a session. The session should be enabled only after the user successfully authenticates himself.Prevention:-1. A user logged into Orkut should not run any untrusted JavaScript or program to prevent the cookie from being stolen.2. On a shared system, the user must log out of Orkut by clicking the"Logout" link. This would delete the session cookies at the browser and another user can not read the cookie value from the browser. Alternatively, the cookie can be removed from the browser.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Style Customized by The Support Guy
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0