Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Logging In
skiddieleet
On your login page, you have it defaulting to automatically log you in each visit or something like that. I'm not one to look around for boxes to uncheck when I login, I just login. I think that's bad practice for a security forum. You should have the box to keep you logged in default to not being checked. That's just my opinion. I see a login box I login, I don't fool around unchecking boxes that are hard to spot anyway. That could be bad in a public place. Peace.
Serhat
true indeed..
but there is a nice Log Out button next to your nickname above.. just use that to log out and you are done..
and anyway I wouldn't recommend you checking out forums and stuff on public places.. I wouldn't anyway
I know what you mean.. but don't think the board should change some stuff cause of people not hitting the log out button when they are done visiting the board..

Serhat
dissolutions
and the password isn't sent over ssl.

the login is not secure in anyway

the box is hardly NOT visible, and frankly i can't see how you would miss it, being right beside the login name portion of the page.

It even clearly states that it's bad practise for a shared computer, and you speak about it being a security site, i believe that anybdy security conscious would look for something such as this, but thats my general opinion.

I also believe that not everybody on this forum will have such tunnel vision to miss these check boxes. (or possibly such bad eye sight and with that, windows has such great accessibility features such as magnification and i believe it even scrolls across the entire page)

But thats just my opinion.

--dissolutions
kuki
we can't fall into paranoia : |~~ if you don't like always login uncheck it. i don't think that my or your acc. has a big value (maybe for us only; i dont think it will beacame 'target') and can make any damage, and i'm sure that admins/mods keep their pass. safe wink.gif
belgther
maybe the remember me option should be unchecked at default... That can be done with a little modification on the PHP script, just a matter of the checkbox default value, and same can also be on the small login screen... Such modifications can easily be done by people with average PHP knowledge, or even beginner knowledge.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.