Project

General

Profile

Actions

Feature #3727

open

Security: Session Hijacking erschweren

Added by Carsten Rose about 7 years ago. Updated 9 months ago.

Status:
New
Priority:
Normal
Assignee:
Support: Web
Target version:
Start date:
13.05.2017
Due date:
% Done:

0%

Estimated time:
Discuss:
Prio Planung:
No
Vote:

Description

  1. Problem 1: durch '[FE][lockIP] = 0' wird der Schutz gegen Session Hijacking fuer FE-User verringert.
  2. Problem 2: in QFQ ist kein 'Session Hijacking' based on changed IP detection implementiert.
Beides koennte leicht implementiert werden:
  • Zu 1)
    • Entweder eine Extension schreiben die gewisse IPs immer zulaesst (z.B. die lokalen IPs) - es gab entsrpechende Extensions.
    • Oder in QFQ diesen Check implementieren (z.B. in dem sich QFQ beendet, sollte der aktuelle FE User einer FE Gruppe angehoeren)
  • Zu 2) implementieren. Am besten aehnlich konfiguriert wird '[FE][lockIP]'
Actions #1

Updated by Carsten Rose almost 7 years ago

  • Target version set to next9
Actions #2

Updated by Carsten Rose about 6 years ago

  • Target version changed from next9 to 18.10.3
Actions #3

Updated by Carsten Rose almost 6 years ago

  • Assignee changed from Carsten Rose to Elias Villiger
Actions #4

Updated by Elias Villiger almost 6 years ago

  • Assignee changed from Elias Villiger to Carsten Rose
Actions #5

Updated by Carsten Rose over 5 years ago

  • Target version changed from 18.10.3 to 18.12.1
Actions #6

Updated by Carsten Rose over 5 years ago

  • Target version changed from 18.12.1 to 141
Actions #7

Updated by Carsten Rose about 5 years ago

  • Target version changed from 141 to QFQCD19 - waere gut
Actions #8

Updated by Carsten Rose over 4 years ago

  • Status changed from New to Some day maybe
Actions #9

Updated by Carsten Rose over 4 years ago

  • Status changed from Some day maybe to New
Actions #10

Updated by Carsten Rose over 4 years ago

  • Target version changed from QFQCD19 - waere gut to next6
Actions #11

Updated by Carsten Rose about 3 years ago

  • Target version changed from next6 to next4
Actions #12

Updated by Carsten Rose over 1 year ago

  • Target version changed from next4 to Check if 'high' is still necessary
Actions #13

Updated by Carsten Rose 9 months ago

  • Assignee changed from Carsten Rose to Support: Web
  • Priority changed from High to Normal
  • Target version changed from Check if 'high' is still necessary to CodingWeek2023
  • Prio Planung set to No
Actions

Also available in: Atom PDF