Losing ability to login on a specific machine Losing ability to login on a specific machine
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Losing ability to login on a specific machine

Started by terrymc1, June 20, 2006, 04:29:51 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

terrymc1

I have a very peculiar situation. I'm running CP 1.48 and if I try to login, eaither as admin or as a user, I see the screen with the "welcome admin" or whatever message and then am redirected to a screen that still has login as an option in the menu. It appears that it is not really logging me in. If I login as admin, I don't get the admin menus and options, etc. The only way around this has been to select "I forgot my password" and let CP send me another password in the process that it goes through. Then I can login and everything is as it should be. But, it does not last. The next time I try to login I'm back to the same situation as I was before.

Note that this does not seem to happening in my laptop. What could be the difference? I'm using IE6 and have refreshed till the cows came home, deleted cookies, deleted temporary files, etc. What could be going on between this particular machine and CP? Why does a password change allow proper login (temporarily)??? Any help is appreciated...

Vargha

Haalaa Boro Ye Chayi Vasam Dorost Kon Ta Man Ye Fekri Be Halet Bokonam ;) Ye Hendooneye Shotoriham Biyar Bizahmat :)
Visit My Site www.Rangarang.co.nr
Check Out My Gallery
www.Rangarang.co.nr/buddies
(https://coppermine-gallery.com/forum/proxy.php?request=http%3A%2F%2Fimg157.imageshack.us%2Fimg157%2F838%2Frangarang4xn.jpg&hash=48b4c3087515cafe09fc6d3f7ee19dce86328d8e)

terrymc1

The site is http://www.my-resource.net/cm1/. I have set up a user called "tester" and the password is "test". Note that this user does not have admin privileges, but when I try to login as tester on my machine it doesn't work, on my laptop it does... Thanks...

terrymc1

I don't know if this is meaningful or not, but I have CP 1.33 installed on another domain and I can log in and out of that installation all day properly using the machine that won't cooperate with my 1.48 installation.

Sami

do you have any firewall or cookie manager app. somthing like zone alarm or norton internet security ?
‍I don't answer to PM with support question
Please post your issue to related board

terrymc1

Quote from: bmossavari on June 20, 2006, 07:12:40 AM
do you have any firewall or cookie manager app. somthing like zone alarm or norton internet security ?

I am running Norton Internet Security 2005 on both the workstation that is giving me problems and the laptop that isn't giving problems. Remember, if I let CP change the password it will work ONCE so it doesn't seem like the firewall would be blocking the admin page redirect or it would never work??

Joachim Müller

Temporarily shut down Norton Internet Security to test if this cures your issue. If yes, look into the so called "privacy" settings. Imo, NIS sucks, luring users into a false sense of security with paranoid privacy/cookie settings.

missmandy

I'm having the very same issue and there aren't any Firewalls or the like on this system.

http://www.josh-jackson.net/images

terrymc1

I've disabled the firewall and it made no difference. Why would cp 3.3 work fine on this machine and not 4.18? And then there is that weird thing that it works with the password change. Did maybe smething change in the way passwords are handled in version 4.xx?

Tranz

Well, there's now password encryption. Do you have that enabled? I don't see how that would result in different things going on on different computers, though.

fulcan

I am having the same problem.  I had 1.4.6 and thought that maybe it was part of the security problem so I did the upgrade to 1.4.8 and still have the problem.  Seems like its very common all of a sudden but only taking place in 1.4.X

I too have tried turniong off Norton internet security and it has not had any impact.

???

Anyone have any ideas?  Its like it recognises you but does not allow the coockie to be planted to enable you to get the admin features.

terrymc1

Quote from: TranzNDance on June 21, 2006, 04:35:24 AM
Well, there's now password encryption. Do you have that enabled? I don't see how that would result in different things going on on different computers, though.

Where do I turn password encryption on and off? I'll change whatever it is set to currently and see if it makes any difference. Also, does CP ever use any port besides port 80? Thanks...

Tranz

Password encryption cannot be turned off once it's enabled... it's a one-way deal.

New 1.4 installations come with it enabled; there's no disabling it. Existing 1.3 galleries that upgrade have the option to enable it.

terrymc1

I had my web hosting service upgrade me from php 4 to php 5 and ever since CP has been working just fine. Logs me in perfectly. Is php 5 a requirement for CP 4.xx that I somehow overlooked?

Sami

No! as documantation said , CPG will work with PHP 4.1.0 or better
‍I don't answer to PM with support question
Please post your issue to related board

terrymc1

Hmmmmm.... Interesting. I didn't think it required version 5 but having my hosting service upgrade me from php 4.4.1 to 5.0.4 caused the problem to "resolve itself." Whatever was messing up the ability to login properly may remain a mystery. All I care is it works now and I am happy! If it flakes out again I'll check back in.

fulcan

Unfortunately, this does not really solve the problem.  Previously I was able to login using 1.4.6.  Then the other day I tried to login to admin and it did not work.  Nothing had changed yet it no longer worked and it appears a lot of people have had the problem. 

I upgraded to 1.4.8 and still have the problem. 

As I was able to login on 1.4.6 and then I wasnt something appears to have affected a number of people.

If anyone has some ideas or a sbetter solution than upgrading to PHP version 5 I would be grateful to hear it.

If you dont own the server the software upgrade to PHP 5 is not necessarily an option.

Thanks