Koozali.org: home of the SME Server

Security Issue

Mark S

Security Issue
« on: June 16, 2002, 10:38:04 AM »
After making configuration changes using Server Manager from a local workstation and performing a reboot, the workstation session remains active in Server Manager without requesting a username and password.  How can this be?  The httpd deamon is allowing root access to the system without requesting a username or password?

MarkS

Jeff C

Re: Security Issue
« Reply #1 on: June 16, 2002, 08:00:58 PM »
Mark,

It's not an SME thing.  Your browser is caching the login and password.  Simply close the browser and you will be challenged for the authentication again.  

-jeff

Rob

Re: Security Issue
« Reply #2 on: June 17, 2002, 05:37:08 PM »
This is why you should ALWAYS log out of your webmail app. If you just browse off to other websites, and leave the browser open, anyone can run your link to your webmail and enter your account, or just use the back button.

rob