Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner

IE 8 Release version is sharing session cookies across browsers

microsoft.public.internetexplorer.general




Recommended Fix - Fix Vista Errors and Optimize Performance


Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 03-23-2009
Steve H
 

Posts: n/a
IE 8 Release version is sharing session cookies across browsers
Hi,

We've got a big problem with IE 8.

With IE 7 you could launch different browser sessions and login to a web
site with different ID's. Each browser window would have it's own session
cookie. Each tab would share the session cookie - which is exactly how it
should intuitively work.

If you do this with IE 8 then there seems to be only ever one session. No
matter how many browsers you open you get the same session and so you can
login as only one user at a time.

This is a problem for us with our own application, but it is also a problem
with all web sites and we have reproduced it with Ebay for example.

I haven't been able to find any settings in the UI to disable this.

Best regards

Steve
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 03-23-2009
VanguardLH
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
Steve H wrote:

> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve


If this is something you can reliably reproduce then maybe you should
tell Microsoft about it directly.

Comment: "Support for Internet Explorer 8 is available at no charge
until 31st December 2009."
MS page: http://preview.tinyurl.com/c4roap
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-25-2009
Ace
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
On Mar 23, 5:06*am, Steve H <Ste...@discussions.microsoft.com> wrote:
> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve


I haven't been able to figure out how to do so either. This is a huge
problem, and it used to exist back in IE4 as well! It made such good
sense to have the session shared between tabs and new windows
generated from a running IE instance, with new IE processes getting a
new session. Argh, this is a huge setback in functionality.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 03-25-2009
Ace
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
On Mar 23, 5:06*am, Steve H <Ste...@discussions.microsoft.com> wrote:
> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve


Steve-

Looks like MS broke this expectation in IE8 (vs how it worked in
IE5,6,7) when they implemented the InPrivate Browsing functionality.
From what I gather, you should get a similar behaviour as you had come
to rely on when you launch an IE8 window with InPrivate Browsing
(Tools > InPrivate Browsing). You can also create a shortcut to
always launch in this mode by passing in the -private option to
iexplore.exe.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 03-25-2009
Cesee
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
On Mar 25, 3:47*pm, Ace <jerah...@gmail.com> wrote:
> On Mar 23, 5:06*am, Steve H <Ste...@discussions.microsoft.com> wrote:
>
>
>
>
>
> > Hi,

>
> > We've got a big problem with IE 8.

>
> > With IE 7 you could launch different browser sessions and login to a web
> > site with different ID's. Each browser window would have it's own session
> > cookie. Each tab would share the session cookie - which is exactly how it
> > should intuitively work.

>
> > If you do this with IE 8 then there seems to be only ever one session. No
> > matter how many browsers you open you get the same session and so you can
> > login as only one user at a time.

>
> > This is a problem for us with our own application, but it is also a problem
> > with all web sites and we have reproduced it with Ebay for example.

>
> > I haven't been able to find any settings in the UI to disable this.

>
> > Best regards

>
> > Steve

>
> I haven't been able to figure out how to do so either. *This is a huge
> problem, and it used to exist back in IE4 as well! *It made such good
> sense to have the session shared between tabs and new windows
> generated from a running IE instance, with new IE processes getting a
> new session. *Argh, this is a huge setback in functionality.- Hide quoted text -
>
> - Show quoted text -


I think that even sharing a session between tabs is a big problem and
it doesn't make sense to me, not to mention that it causes a major
security problem.

For example you can have two tabs, one is secure and one is unsecure,
then close the secure one, and you won't even know that you are still
logged in (clicking a bookmark on the desktop will autmatically log
you in... or somebody else in...)

Another example is XS-Request-Forgery - this session between tabs
thing makes it much easier for the attackers (you just need to open
the email and the secure site in the same browser and click on a link
in the mail...)

Now with IE8 it's real HELL

I think I'm gonna contact microsoft about this, not to mention the
other bugs in IE8 (such as ignoring the no-cache headers which is
another security problem)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 03-25-2009
Eric
 

Posts: n/a
RE: IE 8 Release version is sharing session cookies across browsers
Whoa! BIG problem. I am able to reproduce this. And it's true even if,
before you open the new window, you close the original browser that started
the session! GIANT security problem here. There are a lot of great things
about IE8, but man... there are some really horrible things too!

"Steve H" wrote:

> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 03-25-2009
Eric
 

Posts: n/a
RE: IE 8 Release version is sharing session cookies across browsers
FYI: I just also confirmed it with Bank of America. Log in, copy the URL
from the welcome page, close the browser, open a new browser, paste the URL,
poof, you're logged in. The URL from the BofA welcome page is standard, so
you could just try popping that into web browsers out in the world (internet
cafes, etc.) and eventually you'll be logged into someone's bank account.
This is unbelievably bad.

"Steve H" wrote:

> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 03-26-2009
PA Bear [MS MVP]
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
Please state your full Windows version (e.g., WinXP SP3; Vista SP1), Steve.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Client - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

Steve H wrote:
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a
> problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 03-26-2009
EricLaw
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
This behavior is by-design for IE8. We elected to make session
handling more consistent. Previously, some entry points would create
a new session (e.g. clicking a desktop icon) while others did not
(e.g. File > New Window).

There's a little test page that makes this easy to demo here:
http://www.enhanceie.com/test/sessions/

Now in IE8, new sessions are created explicitly, by clicking File >
New Session, or by starting iexplore.exe with the -nomerge command
line parameter.

I'll be putting up a post on this topic on the IEBlog (blogs.msdn.com/
ie) shortly.

Thanks,

Eric Lawrence
Security Program Manager
Internet Explorer

On Mar 23, 5:06*am, Steve H <Ste...@discussions.microsoft.com> wrote:
> Hi,
>
> We've got a big problem with IE 8.
>
> With IE 7 you could launch different browser sessions and login to a web
> site with different ID's. Each browser window would have it's own session
> cookie. Each tab would share the session cookie - which is exactly how it
> should intuitively work.
>
> If you do this with IE 8 then there seems to be only ever one session. No
> matter how many browsers you open you get the same session and so you can
> login as only one user at a time.
>
> This is a problem for us with our own application, but it is also a problem
> with all web sites and we have reproduced it with Ebay for example.
>
> I haven't been able to find any settings in the UI to disable this.
>
> Best regards
>
> Steve


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 03-26-2009
EricLaw
 

Posts: n/a
Re: IE 8 Release version is sharing session cookies across browsers
<<not to mention the other bugs in IE8 (such as ignoring the no-cache
headers which is another security problem) >>

IE8 does not "ignore" no-cache headers. As specified in RFC2616,
"Cache-Control: no-cache" is simply a directive to the client that it
should not reuse the cached-entry without revalidation. Internet
Explorer supports this directive. (Notably, this directive is
intended to have no bearing whatsoever on whether or not the browser
stores the content in its cache).

To learn more about caching, please see www.enhanceie.com/redir/?id=httpperf

Eric Lawrence
Program Manager
Internet Explorer Security

On Mar 25, 1:50*pm, Cesee <cesar.mar...@gmail.com> wrote:
> On Mar 25, 3:47*pm, Ace <jerah...@gmail.com> wrote:
>
>
>
>
>
> > On Mar 23, 5:06*am, Steve H <Ste...@discussions.microsoft.com> wrote:

>
> > > Hi,

>
> > > We've got a big problem with IE 8.

>
> > > With IE 7 you could launch different browser sessions and login to a web
> > > site with different ID's. Each browser window would have it's own session
> > > cookie. Each tab would share the session cookie - which is exactly how it
> > > should intuitively work.

>
> > > If you do this with IE 8 then there seems to be only ever one session.. No
> > > matter how many browsers you open you get the same session and so youcan
> > > login as only one user at a time.

>
> > > This is a problem for us with our own application, but it is also a problem
> > > with all web sites and we have reproduced it with Ebay for example.

>
> > > I haven't been able to find any settings in the UI to disable this.

>
> > > Best regards

>
> > > Steve

>
> > I haven't been able to figure out how to do so either. *This is a huge
> > problem, and it used to exist back in IE4 as well! *It made such good
> > sense to have the session shared between tabs and new windows
> > generated from a running IE instance, with new IE processes getting a
> > new session. *Argh, this is a huge setback in functionality.- Hide quoted text -

>
> > - Show quoted text -

>
> I think that even sharing a session between tabs is a big problem and
> it doesn't make sense to me, not to mention that it causes a major
> security problem.
>
> For example you can have two tabs, one is secure and one is unsecure,
> then close the secure one, and you won't even know that you are still
> logged in (clicking a bookmark on the desktop will autmatically log
> you in... or somebody else in...)
>
> Another example is XS-Request-Forgery - this session between tabs
> thing makes it much easier for the attackers (you just need to open
> the email and the secure site in the same browser and click on a link
> in the mail...)
>
> Now with IE8 it's real HELL
>
> I think I'm gonna contact microsoft about this, not to mention the
> other bugs in IE8 (such as ignoring the no-cache headers which is
> another security problem)- Hide quoted text -
>
> - Show quoted text -


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Session cookies enabled but bank website says they are not Maree microsoft.public.internetexplorer.general 4 09-27-2009 17:26
enabling session cookies for IE7 mamasgolfing microsoft.public.internetexplorer.general 3 02-03-2009 20:41
problems with session cookies in IE 7 Mark microsoft.public.internetexplorer.general 3 01-18-2009 01:49
IE7 cookies/session/connection problem sean microsoft.public.internetexplorer.general 3 12-09-2008 15:54
Re: IE7 allow cookies for session Jason microsoft.public.internetexplorer.general 2 09-21-2008 02:16




All times are GMT +1. The time now is 02:24.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120