1 (edited by pia 2014-06-03 11:05:48)

Topic: Session kidnapping?

Hi

I'm confronted with an issue where user1 is uploading three files (a tiny "start"-file, the actual file and a tiny "end"-file).
sometimes this user isn't able to upload all three files. I found this in the logs.

2014-06-02 00:00:06 [555]New client [user1] from [www.xxx.yyy.zzz]
2014-06-02 00:00:06 [555][user1][www.xxx.yyy.zzz]Start upload into file '/home/user1/file_02.06.2014.zip.start'
2014-06-02 00:00:06 [555][user1][www.xxx.yyy.zzz]End upload into file '/home/user1/file_02.06.2014.zip.start'
2014-06-02 00:00:06 [555][user1][www.xxx.yyy.zzz]Start upload into file '/home/user1/file_02.06.2014.zip'
2014-06-02 00:00:51 [700]New client [user2] from [some.hostname.com]
2014-06-02 00:00:52 [700][user2][some.hostname.com]Quit.
2014-06-02 00:05:51 [856]New client [user2] from [some.hostname.com]
2014-06-02 00:05:52 [856][user2][some.hostname.com]Quit.
2014-06-02 00:10:51 [1036]New client [user2] from [some.hostname.com]
2014-06-02 00:10:53 [1036][user2][some.hostname.com]Quit.
2014-06-02 00:15:52 [1200]New client [user2] from [some.hostname.com]
2014-06-02 00:15:53 [1200][user2][some.hostname.com]Quit.
2014-06-02 00:16:01 [555][user2][some.hostname.com]End upload into file '/home/user1/file_02.06.2014.zip'
2014-06-02 00:16:01 [555][user2][some.hostname.com]Quit.
2014-06-02 00:20:51 [1543]New client [user2] from [some.hostname.com]
2014-06-02 00:20:53 [1543][user2][some.hostname.com]Quit.
2014-06-02 00:25:51 [1700]New client [user2] from [some.hostname.com]
2014-06-02 00:25:53 [1700][user2][some.hostname.com]Quit.

bewteen

2014-06-02 00:16:01 [555][user2][some.hostname.com]End upload into file '/home/user1/file_02.06.2014.zip'

and

2014-06-02 00:16:01 [555][user2][some.hostname.com]Quit.

user1 tries to upload /home/user1/file_02.06.2014.zip.ende but receives a permission denied.

Can anybody explain or help me with that?

Thanks a lot in advance smile

Re: Session kidnapping?

Hi,

Upgrade to last version of MySecureShell this bug is fixed wink

Re: Session kidnapping?

I did upgrade the minute after i posted here and the problem didn't reappear.

Thanks for confirming it was a bug.