Discussion in 'Tomato Firmware' started by flump, Mar 16, 2007.

  flump

    flump Guest

    Hi all,

    Just to mention a funny I've noticed with IE7 against Tomato 1.05.0977 on a WRT54GS V1.1, when you use the 'Logout' function.

    In Firefox if you logout, do not close down the browser session and then subsequently navigate back to the router web interface you are prompted to log in again as you would expect, however in IE7 if you do the same thing it allows you full access.

    Can anyone else reproduce this small but possibly important (in terms of security) issue?
  pharma

    pharma Network Guru Member

    It occurs only if you leave your browser window open. If you close your browser window (all tabs) and re-open a new one you will get the prompt.

    I've seen this behavior on a few internet websites that require Username & pw. It's why some banking sites tell you to close your browser window completely.
