Page 1 of 1

login secruity issue

Posted: Tue Aug 31, 2010 1:06 pm
by renegadze
Not sure if it's a bug.....but definately a potential security problem.

I can login to quantum, save cookies, completely close down my browser, re-open browser, go to quantum and I am automatically logged in. I only have to relog if I wait more then 30 mins to re-open browser.

surely this would make breaches via script possible?

Re: login secruity issue

Posted: Tue Sep 07, 2010 4:13 am
by Neimenljivi
Which browser do you use?
I use mozilla firefox and opera and neither allow me to stay logged in (even if I use both at the same time) after I close and reopen it.

~Jack

Re: login secruity issue

Posted: Tue Sep 07, 2010 4:21 am
by [BoT] Jason
Can only be exploited by those living with you as a script gets kicked after 3 hours?

Re: login secruity issue

Posted: Tue Sep 07, 2010 9:08 am
by renegadze
Jason... wrote:Can only be exploited by those living with you as a script gets kicked after 3 hours?


and what stops someone logging in every 3 hours to reset the script?

@ Jack - I use Mozilla Firefox, and I just tested again, and can confirm I can still remain logged in after closing the window down.

Also I can also open multiple instances of Quantum without having to re-login. Now I don't mean I can right click and "open in new window". But if say I login to quantum, then open a blank tab, I can go direct to a quantum page from that blank tab without relogging.....(I could be wrogn but don't believe main allows this).

Re: login secruity issue

Posted: Tue Sep 07, 2010 9:10 am
by Neimenljivi
It might be your browser settings then as if I remember correctly from comps in school, it doesn't work there either ;) Try choosing your cookies to be deleted every time you shut down the browser.

~Jack

Re: login secruity issue

Posted: Tue Sep 07, 2010 9:13 am
by [BoT] Jason
You can only loggin on multiple accounts with different browsers?

And Logging in three hours with a bank script is highly unprofitable in Q as your chances of neg naq are so high.

Re: login secruity issue

Posted: Tue Sep 07, 2010 9:29 am
by renegadze
Jason... wrote:You can only loggin on multiple accounts with different browsers?

And Logging in three hours with a bank script is highly unprofitable in Q as your chances of neg naq are so high.


Well I'm not saying anyone is cheating....just that it is possible......and it is highly profitable if you have a decent def, as a lot may not farm for 1 turns income