Invalid Sessions

New to the board? Please check out the rules here first. We will also post news about the website here.
Site Admin
Posts: 9282
Joined: Fri Jun 06, 2003 7:34 am
Location: London, Ontario

Invalid Sessions

Postby BossHog » Wed Jul 14, 2004 9:54 am

This is a note to members who may experience an invalid session error.

This error is unfortunately caused by a setting on the individual user's computer, and as such, is sometimes very difficult to figure out.

However, the most common cause of the error is when users are trying to access the forum with the AOL browser. For some reason, the phpBB forum and AOL don't seem to like each other much. if you are one of these users, simply navigate to the message board via Microsoft internet Explorer, and the problem will probably disappear.

Unfortunately, if it does not, there's not much we can do. If you have the knowledge to do so, you can also try lowering your internet security settings slightly to see if it makes the problem go away.

I hope this helps a few of you.
Last edited by BossHog on Sat Jun 09, 2007 9:02 am, edited 1 time in total.
Sean Taylor was one of a kind, may he rest in peace.

+++
Posts: 4448
Joined: Wed Oct 01, 2003 2:02 pm

Postby NikiH » Wed Jul 14, 2004 10:04 am

Thanks BossHog. Sorry I should have known it was freaking AOL, they cause problems with everything I try to do. We tried to get rid of them but were talked back into staying.
Time to say Buh bye AOL! Thanks again.
Whenever I start to get blue, I just breathe!

My favortie line from the Simpsons:

Flanders: "Looks like someone is having a pre-rapture party!"

Homer: "No Flanders, it's a meeting of gay witches for abortion , you wouldn't be interested!"

Site Admin
Posts: 9282
Joined: Fri Jun 06, 2003 7:34 am
Location: London, Ontario

Postby BossHog » Wed Jul 14, 2004 10:08 am

It's okay that you have AOL... just login through AOL, but then instead of browsing with the AOL browser, get into the habit of using the IE browser.

It's the AOL browser that is touchy, not the service... of course, I live in Canada so I'm the wrong one to ask.
Sean Taylor was one of a kind, may he rest in peace.

---
User avatar
Posts: 18569
Joined: Mon Jul 28, 2003 12:55 pm
Location: AJT

Postby Chris Luva Luva » Thu Jul 22, 2004 9:00 pm

It does it for me sometimes with my IE browser. I just make a habit of highlighting my post and copying it so if I get the invalid session and does keep my post saved, I can just paste it in and keep moving.

Heres some irony, I tried to post this post and I got an invalid session! ROTFALMAO
Fios - Arbiter of All Positive Knowledge

Kaz - "Was kinda obvious since we all know you're not a moron"

---
User avatar
Posts: 18569
Joined: Mon Jul 28, 2003 12:55 pm
Location: AJT

Postby Chris Luva Luva » Fri Feb 04, 2005 8:47 pm

Boss, Im not sure if anything has been done to the server since I've last posted in this thread but this error has dissapeared completely on my end.

I just wanted to give you the heads up.
Fios - Arbiter of All Positive Knowledge

Kaz - "Was kinda obvious since we all know you're not a moron"

Site Admin
Posts: 9282
Joined: Fri Jun 06, 2003 7:34 am
Location: London, Ontario

Postby BossHog » Wed Mar 15, 2006 1:48 pm

Here's the technical reasoning behind why some users get invalid sessions:

phpBB2 uses sessions to keep track of users as they browse the board. These sessions use a combination of a unique session id and the users IP to identify each user. We make use of the IP as an extra safe-guard to help prevent sessions being hijacked (by discovering the unique session id).

Unfortunately this only works when the users IP is constant as they browse the board. For most users this will be the case. However certain providers route their users via a cluster of proxys. In some cases, particularly AOL this results in different IPs being forwarded as the user moves between pages. We take account of this by not checking the entire IP but only the first "three quads". Again in most cases this will be fine. However again AOL uses IPs which can vary so much that checking only the first two quads results in a fairly static IP being available for session validation.

If you are experiencing problems related to this you can make a small change to the code. Please note that reducing the IP validation length does potentially increase the risk of sessions being hijacked (this is something for you to consider, phpBB Group takes no responsibility should anything happen!). The change requires you to...




The bold part is the reason I don't want to change the settings, so I'm afraid until a better solution comes up... using IE to navigate to the board, intead of AOL's browser is our only solution.
Sean Taylor was one of a kind, may he rest in peace.

piggie
User avatar
Posts: 106
Joined: Mon Sep 27, 2004 10:48 am
Location: Alexandria, VA

Postby LukeA » Thu Jul 20, 2006 11:57 am

It sounds like it's the AOL service that is the problem and not just the browser. If AOL is routing the user through different IPs I don't think it will matter what browser the AOL user is using, they will still encounter this error.
Go Skins!

Return to Site News & Welcome Wagon