Thursday 03 September 2009 9:09:03 am
Hello, first of all it there a special forum for security questions? Didn't find one. Now the question: Something VERY strange just happend:
I just logged in to ez publish site of a customer with my user called "nimran". some minutes later the customer also logged in with his own user.
For some reason eZ displayed my username on his logout button. He could see "logout (nimran)" link in his browser and sent me a screenshot of that!!!
He definitely does not know my password. also I trust him, that he did not hack it or wuteva. it happend accidentally! It seemed that eZ publish mixed up the sessions, so he logged in with his data, but got my user!!! Unfortunately I don't know if he really got my permissions, or if it was just a display bug, as he logged out, before we could check that. but eZ definitely showed him logged in as me! how can this happen??
If eZ really mixed up the sessions / user permissions for any reason, it might be a very dirty threading bug or likewise. If it was just a bug in display, it might be a caching problem. Is this really possible??? Apache is running in prefork mode with php 5.2.0 and eZ publish 4.01.all caches are activated. Static cache is active as well, but should not be involed because it's generated without login by the generator. The site runs for almost a year now and we never experienced problems like that before!! I am very afraid about what that just was..... Any ideas on that??
|