FUDforum
Fast Uncompromising Discussions. FUDforum will get your users talking.

Home » FUDforum Development » Bug Reports » Google links take you to different users profiles
Show: Today's Messages :: Unread Messages :: Show Polls :: Message Navigator
| Subscribe to topic | Bookmark topic 
Switch to threaded view of this topic Create a new topic Submit Reply
Google links take you to different users profiles [message #186558] Tue, 30 September 2014 15:58 Go to next message
timwalter is currently offline  timwalter   United Kingdom
Messages: 12
Registered: June 2010
Karma: 0
Junior Member
add to buddy list
ignore all messages by this user
Hi I've been admin to a fudforum for some time but seldom had a problem til the last month or two...

Several users started reporting that they were arriving at the forum and seeing other peoples log in details. I couldn't see the problem initially til today someone detailed it a bit more. Specifically when the search for the forum on google and then click some links it takes them to a thread and it appears to all intents and purposes that they are logged in as someone else.

Today I did it and saw it to be true.

The parameters so far seem to be that they get there via a direct google link.
I think they are all connecting via NHSnet, which effectively is a giant VPN (i've tried from home on a Mac and didn't show up.) NHSnet is the network used within the British National Health Service
The example google link that showed it was

http://www.emisnug.net/forum/index.php?t=thread&frm_id=2&

As I say it happens via NHSnet /IE definitely but not from home / Mac /Safari/Firefox

When I demonstrated it myself I could get into account settings in profile for the "other person" though didn't see if I could actually change it.

I strongly think it relates to the NHSnet vpn, and see it as a potentially massive problem if indeed it is as I surmise. Unfortunately I don't have the skills needed to assess and define if it is true. I don't know how to take this forward... Help please!

FUDforum version: 3.0.5
PHP version: 5.3.3
PHP built on: Linux server88-208-250-198.live-servers.net 2.6.32-279.el6.x86_64 #1 SMP Fri Jun 22 12:19:21 UTC 2012 x86_64
Database type: mysql (mysql)
Database version: 5.1.73
Web server: Apache/2.2.15
Web Server load: 0.36
Web server to PHP interface: cgi-fcgi
Relevant PHP settings:
Safe mode: OFF
Open basedir: none
Display errors: ON
File uploads: ON
Maximum file upload size: 2M
Magic quotes: OFF
Output buffering: Yes
Disabled functions: none
PSpell support: No
Zlib support: Yes

[Updated on: Tue, 30 September 2014 15:58]

Report message to a moderator

Re: Google links take you to different users profiles [message #186565 is a reply to message #186558] Thu, 02 October 2014 14:38 Go to previous messageGo to next message
cpreston is currently offline  cpreston   United States
Messages: 160
Registered: June 2012
Location: Oceanside
Karma: 6
Senior Member
add to buddy list
ignore all messages by this user
Can you post some screen captures for those of us that don't have IE?
Re: Google links take you to different users profiles [message #186571 is a reply to message #186565] Thu, 02 October 2014 16:40 Go to previous messageGo to next message
timwalter is currently offline  timwalter   United Kingdom
Messages: 12
Registered: June 2010
Karma: 0
Junior Member
add to buddy list
ignore all messages by this user
I can but
a. Right this minute i can't reproduce it
b. There nothing helpful to see.

In essence (and I know I didn't describe it particularly well...) People were viewing pages and at the top instead of their own name logged in it was another person

i.e. Mary logs in as a user. Peter logs in
"The next day" Peter clicks a url (google) and instead of Peters details, he appears to be logged in with Mary's details It looks like Peter could even see Mary's profile details though unfortunately I didn't drill down as to how far...

As far as I know it seemed to be two registered users getting mixed, though obviously it would be unlikely a non registered person would bother to report a problem to me.

Since then I have changed two settings in the admin page.

Session cookies, and Session IP Validation

So far I can't reproduce it, and not too keen to experiment on a live system though I accept that won't help resolving it if it is a problem
Re: Google links take you to different users profiles [message #186573 is a reply to message #186571] Thu, 02 October 2014 19:46 Go to previous messageGo to next message
cpreston is currently offline  cpreston   United States
Messages: 160
Registered: June 2012
Location: Oceanside
Karma: 6
Senior Member
add to buddy list
ignore all messages by this user
So you're saying you believe you've fixed it by changing these settings? What did you change them to (for posterity)?
Re: Google links take you to different users profiles [message #186580 is a reply to message #186573] Fri, 03 October 2014 15:55 Go to previous messageGo to next message
timwalter is currently offline  timwalter   United Kingdom
Messages: 12
Registered: June 2010
Karma: 0
Junior Member
add to buddy list
ignore all messages by this user
I switched both of them on. (by default they seem to be off as I would have accepted the defaults originally)

I do think there is a problem albeit maybe quite specific (I think it is the NHSnet sharing IPs or whatever that is the problem not Internet Explorer.) thats worthy of attention if people can see each others profiles etc

BW Tim
Re: Google links take you to different users profiles [message #186581 is a reply to message #186580] Fri, 03 October 2014 16:55 Go to previous message
cpreston is currently offline  cpreston   United States
Messages: 160
Registered: June 2012
Location: Oceanside
Karma: 6
Senior Member
add to buddy list
ignore all messages by this user
OK. I'll wait to see if anyone else reports this. It would seem like a pretty big deal.
Quick Reply
Formatting Tools:   
  Switch to threaded view of this topic Create a new topic
Previous Topic: Search highlighting breaks upper-case
Next Topic: Captch is broken on the FUDforum Wiki
Goto Forum:
  

-=] Back to Top [=-
[ Syndicate this forum (XML) ] [ RSS ]

Current Time: Mon Jun 26 03:08:57 EDT 2017

Total time taken to generate the page: 0.00689 seconds