Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 24, 2012, 10:01:34 AM

Pages: [1]   Go Down
  Print  
Author Topic: Why doesn't logout work on CPANEL ?  (Read 667 times)
sickteatoo
Newbie
*
Offline Offline

Posts: 3


WWW
« on: July 30, 2003, 09:45:01 PM »

I'm new to Lunarforums.  A programmer by trade and lots of web experience.

All I want to do is logout of CPANEL.  When I do I expect that I am "logged out".  Why is it that in IE that I can hit the little "logout" icon in the upper right and I get this:

mscmotocross.com has been logged out. Thanks for using Cpanel!
Last login from: xxxxx.optonline.net
Click here to log in again

But it has no effect.  If I hit the back button I get a popup window asking me to put in my ID again but all I have to do is cancel it a few times and I have full access to CPANEL.    If I cancel my IE session then it will prompt me for a userid and password once again.  I am on 6.0 using all the Microsoft defaults.  Setting page refresh to "every time" has no effect.  If I manually refresh it has no effect.  And I have full access!  Can do whatever I want WITHOUT signing in AFTER I have logged off and got the above message.  I also went to CONTENT and blew out all my passwords and forms.  Tried killing all cookies and stored pages.  Went to "advanced" and told it not to accept stuff.  No impact.

Now, 6.2 Netscape is a somewhat better.  It works as it should.  However, if I hit the "click here to login again" then it gets itself into stupid mode just like IE and now when I logout (and get the above message) I can still hit the back button and get to CPANEL without relogging in.  

Now, I put up 1 website already and wish to purchase another account tonight.  But I have never seen anything like this before and it makes me think that Lunar security is second rate.  Please say this isn't so. Please say this is my fault and point out why.  I like Lunar and want to purchase a PREMIUM account for a business tonight !  But security is job #1.  So I await your guidance.

sickteatoo
Logged
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #1 on: July 31, 2003, 03:00:54 AM »

Hmm not sure but it's always been my experience that if I want to make sure I'm logged out of an authorized area,  I should close any browser windows.
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
sickteatoo
Newbie
*
Offline Offline

Posts: 3


WWW
« Reply #2 on: July 31, 2003, 06:09:04 AM »

Well, the whole reason this upset me so much is that with IE 5.5 I could hit logoff and then shut down the entire browser and then I could get back in anyway by cancelling the authentication requests.  Works the same way on secured sign in too (sirius).  I upgraded to IE 6.0 and at least it shuts down now if I kill the whole browser (thank god for that).

Clearly by hitting "logoff" on CPANEL I would expect the server to drop authentication.  It clearly has attempted to do that, as it now barks at me a few times with an authentication panel, but after 3 cancels I am in.  Something is dreadfully wrong.  This needs to be brought to someone's attention.  And you know, its nice to think you shut down your browser but if you have a million windows open its not so easy to be sure you got that "straggler" window.  Result:  you did not "LOGOFF" after you "LOGGED OFF" (and that's after Lunar sent you a nice clear message stating the success of your logoff explicitely).  And even on THAT PANEL I can hit the backbutton and get back in after cancelling authentication requests.

sickteatoo
Logged
jinyao
Newbie
*
Offline Offline

Posts: 5


« Reply #3 on: August 03, 2003, 08:12:57 PM »

generally, I do not trust any site's "logout" function if it uses "BASIC" authorization -- that is, using a browser pop up window asking your user name and password -- my web development experience tells me the only sure way logging off from this kind of sites is closing all browser windows.
Logged
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #4 on: August 04, 2003, 06:01:25 AM »

I have to agree with jinyao.

I can hit the back button on any .htaccess authorization area I go to on the 'net and see where I was inside the authorized area.
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
sickteatoo
Newbie
*
Offline Offline

Posts: 3


WWW
..
« Reply #5 on: August 12, 2003, 11:31:13 AM »

Then the word "logout" should be changed to "home" on CPANEL.

You don't specifically state you are doing something, confirm the message to the panel operator that "all is well" with their request and then fail to do it.  

And because Basic Authorization is used to "accept" the userid has absolutely no bearing on whether the EXE's should operate in the system.  It could very well have a second layer of custom security that when someone "logs off" that inner security is revoked.  Noone could possibly know this therefore noone can state that is how Lunar works because it uses Basic Authorization.  If one can accept logic like that then one isn't being very imaginative.  

Considering the overwhelming power of CPANEL I still find this unacceptable.  I will deal with it though.  

Sic t 2
Logged
flipster
Trekkie
**
Offline Offline

Posts: 10


« Reply #6 on: August 14, 2003, 05:45:00 AM »

A similar security problem happens when using webmail! I log out of Horde, quit the browser application. Fire up IE, look at history and click on mail inbox. The Horde login page pops up with my username and password already filled in. One click on the source reveals my pssword to the world!
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: