Paul's Resource Site

Everything else that doesn't fall into one of the other PB categories.
User avatar
Psychophanta
Always Here
Always Here
Posts: 5153
Joined: Wed Jun 11, 2003 9:33 pm
Location: Anare
Contact:

As a wish

Post by Psychophanta »

Hallo, Paul.

As a wish, at your site i miss the posibility about to delete or edit a user resource "in situ".

I mean, each user, with his own name and pass to your site, could change, or delete his own snippet, app, game, etc.
User avatar
fsw
Addict
Addict
Posts: 1603
Joined: Tue Apr 29, 2003 9:18 pm
Location: North by Northwest

Post by fsw »

Hi Paul,
when I go to your site and see in the URL field:
How comes :?:
Don't you think that this is a security hole :?:
Well I do :!:

Never ever I see my password in the URL field.

Besides: I didn't sign up to your site.

The only thing I did over an year ago was to sign-up in your forum that you had back then.

I don't think it's appropriate to get a password from a forum database and publish it in the URL field of a Internet client or use it for a different purpose like as user information for your site.

Is there a possibility to kill my whole data in your database :?:

I am to provide the public with beneficial shocks.
Alfred Hitshock
Karbon
PureBasic Expert
PureBasic Expert
Posts: 2010
Joined: Mon Jun 02, 2003 1:42 am
Location: Ashland, KY
Contact:

Post by Karbon »

While odd, it's not anymore insecure than anything else not encrypted (SSL). The only additional security hazard I can see is if you were to give that link to someone without seeing that it contained your username and password..

Generally the way I do my web based login stuff is the username and password is passed from the client to the server once, and generally over SSL. Then a "logged in" flag (either a cookie or other session variable) is set to true and a "permission" value is associated with the session to control user access..
-Mitchell
Check out kBilling for all your billing software needs!
http://www.k-billing.com
Code Signing / Authenticode Certificates (Get rid of those Unknown Publisher warnings!)
http://codesigning.ksoftware.net
Post Reply