Welcome Guest, Not a member yet? Register   Sign In
Matching the User-Agent in the Session Class
#14

[eluser]caleblloyd[/eluser]
I agree that it is probably this version of IE8 falling back to compatibility mode that causes the UA to change. My web application goes through a series of redirects to pass session data across 2 domains so that the user is automatically authenticated upon getting to the second domain. It is possible that the version of IE8 I am using flips into compatibility mode upon 2 or more redirects within one page request.

I work in an office with ~15 computers with IE8 and can only recreate the bug on 1 of the computers. So it is very possible that this computer has a different minor version of IE8 with this bug and it got fixed in a later IE8 update.

In response to WanWizard-

Quote:Because it’s a security feature, and nobody has ever seen a browser that alters it’s UA string before?

I'd like to reiterate:

Quote:Most people that are capable of understanding how to steal a cookie over an unsecured connection are also capable of spoofing the user-agent quite easily, so I do not think this is a strong enough argument to call for always matching the user-agent.

One common unsecured cookie-stealing Firefox Extension, Firesheep, even has a checkbox to automatically match the UA, so this is an easily defeated "security feature".

And I have found other instances (I will admit, they are rare) of people running into the same IE bug that I have.


In response to Hoopoe-

Quote:so changing sess_match_useragent to FALSE will solve it ?

Yes, that fixes the problem.


Messages In This Thread
Matching the User-Agent in the Session Class - by El Forum - 06-07-2011, 02:41 PM
Matching the User-Agent in the Session Class - by El Forum - 06-07-2011, 03:13 PM
Matching the User-Agent in the Session Class - by El Forum - 06-07-2011, 03:23 PM
Matching the User-Agent in the Session Class - by El Forum - 06-07-2011, 03:34 PM
Matching the User-Agent in the Session Class - by El Forum - 06-07-2011, 03:55 PM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 12:27 AM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 01:02 AM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 01:42 PM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 02:09 PM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 02:11 PM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 04:25 PM
Matching the User-Agent in the Session Class - by El Forum - 06-08-2011, 11:52 PM
Matching the User-Agent in the Session Class - by El Forum - 06-09-2011, 01:13 AM
Matching the User-Agent in the Session Class - by El Forum - 06-09-2011, 01:51 PM
Matching the User-Agent in the Session Class - by El Forum - 06-10-2011, 01:11 AM
Matching the User-Agent in the Session Class - by El Forum - 06-10-2011, 02:10 AM
Matching the User-Agent in the Session Class - by El Forum - 06-11-2011, 07:17 AM
Matching the User-Agent in the Session Class - by El Forum - 06-11-2011, 07:31 PM
Matching the User-Agent in the Session Class - by El Forum - 07-01-2011, 04:01 AM
Matching the User-Agent in the Session Class - by El Forum - 07-01-2011, 04:08 AM
Matching the User-Agent in the Session Class - by El Forum - 07-01-2011, 04:11 AM



Theme © iAndrew 2016 - Forum software by © MyBB