Login - Password - Bypassable

Report & discuss bugs found in SABnzbd
Forum rules
Help us help you:
  • Are you using the latest stable version of SABnzbd? Downloads page.
  • Tell us what system you run SABnzbd on.
  • Adhere to the forum rules.
  • Do you experience problems during downloading?
    Check your connection in Status and Interface settings window.
    Use Test Server in Config > Servers.
    We will probably ask you to do a test using only basic settings.
  • Do you experience problems during repair or unpacking?
    Enable +Debug logging in the Status and Interface settings window and share the relevant parts of the log here using [ code ] sections.
Post Reply
alexaa
Newbie
Newbie
Posts: 19
Joined: May 4th, 2008, 10:37 pm

Login - Password - Bypassable

Post by alexaa »

I noticed today that, if you open sabnzbd (in Windows), when prompted for a password, you can close the window and navigate to sab's regular address (http://localhost:8080/sabnzbd/) and you are logged in; bypassing any password requirements.

I thought I would mention this.
User avatar
switch
Moderator
Moderator
Posts: 1380
Joined: January 17th, 2008, 3:55 pm
Location: UK

Re: Login - Password - Bypassable

Post by switch »

You probably have a cached copy/still valid cookie. It is impossible to bypass the login in the manner you describe.
Post Reply