From a862fec9a329c449b808e8d888764cbc9cc0bc19 Mon Sep 17 00:00:00 2001 From: Robin Appelman Date: Wed, 14 Dec 2011 13:26:34 +0100 Subject: make remember login token also dependent on password to protect against some brute force attacks on this token --- index.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'index.php') diff --git a/index.php b/index.php index 558733e1cda..2d759d68d7d 100644 --- a/index.php +++ b/index.php @@ -88,7 +88,7 @@ else { if(defined("DEBUG") && DEBUG) { OC_Log::write('core','Setting remember login to cookie',OC_Log::DEBUG); } - $token = md5($_POST["user"].time()); + $token = md5($_POST["user"].time().$_POST['password']); OC_Preferences::setValue($_POST['user'], 'login', 'token', $token); OC_User::setMagicInCookie($_POST["user"], $token); } -- cgit v1.2.3