Security warning triggered by simultaneous requests

Created on 28 October 2008, about 16 years ago
Updated 14 January 2025, 7 days ago

Moshe reports a lot of "Stolen Persistent Login session for user ..." watchdog messages at groups.d.o.

This error only occurs when PL sees a browser delivering a cookie it should not have. Generally this means an attack occurred. But if I suppose that the attack is less likely than a bug or other unexpected situation, I should look for an alternative explanation. I can think of one:

Suppose a user's browser is configured to prompt for cookies instead of just accepting them. When they log in with user/pass, they explicitly accept the TWO cookies (session and PL) they are given. When they later return and use the PL cookie, it will work, and PL will issue a *new* PL cookie, and *maybe the user chooses not to accept this one*, thus keeping the old one. Then, the *next* time the user tries to use the PL cookie, the error will be generated.

I asked the one user with an entry for this in the g.d.o logs about their situation.

πŸ› Bug report
Status

Closed: outdated

Version

1.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States bjaspan

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024