Good evening
Now I also have the life headers:
First: Just open the page
http://blog.rince.de/
Code: Select all
http://blog.rince.de/
GET / HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: 0
Cache-Control: no-cache, pre-check=0, post-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
X-Blog: Serendipity
Content-Type: text/html; charset=UTF-8
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
----------------------------------------------------------
http://blog.rince.de/plugin/checkautobackup
GET /plugin/checkautobackup HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:01 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: 0
Cache-Control: no-cache, pre-check=0, post-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
X-Blog: Serendipity
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
----------------------------------------------------------
The Cookie has the following content:
Code: Select all
sudo more /var/lib/php5/sess_dc2279ad1ad90e3473f5e4ec5e2ce06c
SERVER_GENERATED_SID|b:1;serendipityLanguage|s:2:"de";serendipityAuthedUser|b:0;no_smarty|N;HTTP_REFERER|s:21:"http://blog.rince.de/
";
Then I log myself in:
Code: Select all
http://blog.rince.de/admin
GET /admin HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 302 Found
Date: Tue, 18 Mar 2008 22:32:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: 0
Cache-Control: no-cache, pre-check=0, post-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
X-Blog: Serendipity
Location: http://blog.rince.de/serendipity_admin.php
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/serendipity_admin.php
GET /serendipity_admin.php HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
Content-Length: 4205
Content-Type: text/html; charset=UTF-8
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/serendipity_admin.css
GET /serendipity_admin.css HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/css,*/*;q=0.1
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.php
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: Tue, 18 Mar 2008 23:32:17 GMT
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
X-Blog: Serendipity
Content-Length: 6292
Content-Type: text/css; charset=UTF-8
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/templates/default/admin/pluginmanager.css
GET /templates/default/admin/pluginmanager.css HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12)Gecko/20080201 Firefox/2.0.0.12
Accept: text/css,*/*;q=0.1
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.php
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
Last-Modified: Thu, 01 Jun 2006 11:18:53 GMT
Etag: "27870-3f4-d547c140"
Accept-Ranges: bytes
Content-Length: 1012
Content-Type: text/css
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/templates/carl_contest/admin/img/background.png
GET /templates/carl_contest/admin/img/background.png HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.css
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
Last-Modified: Wed, 08 Feb 2006 16:35:26 GMT
Etag: "278bc-1f0-15488f80"
Accept-Ranges: bytes
Content-Length: 496
Content-Type: image/png
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=98
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/templates/carl_contest/admin/img/infobar_background.png
GET /templates/carl_contest/admin/img/infobar_background.png HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.css
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
Last-Modified: Wed, 08 Feb 2006 16:35:26 GMT
Etag: "278bd-fc-15488f80"
Accept-Ranges: bytes
Content-Length: 252
Content-Type: image/png
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=98
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/templates/carl_contest/admin/img/button_background.png
GET /templates/carl_contest/admin/img/button_background.png HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12)Gecko/20080201 Firefox/2.0.0.12
Accept: image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.css
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
Last-Modified: Wed, 08 Feb 2006 16:35:26 GMT
Etag: "278be-880-15488f80"
Accept-Ranges: bytes
Content-Length: 2176
Content-Type: image/png
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=97
Connection: Keep-Alive
----------------------------------------------------------
http://blog.rince.de/serendipity_admin.php
POST /serendipity_admin.php HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.php
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
Content-Type: application/x-www-form-urlencoded
Content-Length: 104
serendipity%5Baction%5D=admin&serendipity%5Buser%5D=xxx&serendipity%5Bpass%5D=zzz&submit=Login+%3
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:26 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
Content-Type: text/html; charset=UTF-8
Set-Cookie: serendipity[old_session]=dc2279ad1ad90e3473f5e4ec5e2ce06c;
expires=Thu, 17-Apr-2008 22:32:26 GMT; path=/; domain=127.0.0.1:1113
Set-Cookie: serendipity[author_token]=761fc0c2fd89d9ab000243d9a3f3304c114746c8; expires=Thu, 17-Apr-2008 22:32:26 GMT; path=/; domain=127.0.0.1
Set-Cookie: serendipity[userDefLang]=de; expires=Thu, 17-Apr-2008 22:32:26 GMT; path=/; domain=127.0.0.1:1113
Set-Cookie: serendipity[author_information]=deleted; expires=Mon, 19-Mar-2007 22:32:25 GMT; path=/; domain=127.0.0.1
Set-Cookie: serendipity[author_information_iv]=deleted; expires=Mon, 19-Mar-2007 22:32:25 GMT; path=/; domain=127.0.0.1
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=97
Connection: Keep-Alive
Transfer-Encoding: chunked
----------------------------------------------------------
The Cookie shows the following content:
Code: Select all
sudo more /var/lib/php5/sess_dc2279ad1ad90e3473f5e4ec5e2ce06c
SERVER_GENERATED_SID|b:1;no_smarty|N;serendipityLanguage|s:2:"de";serendipityAuthedUser|b:1;HTTP_REFERER|s:42:"http://blog.rince.de/
serendipity_admin.php";author_token|s:40:"761fc0c2fd89d9ab000243d9a3f3304c114746c8";serendipityUser|s:5:"xxx";serendipityRealname|
s:5:"rince";serendipityPassword|s:32:"x";serendipityEmail|s:15:"foo@bar";serendipityAuthorid|
s:1:"1";serendipityUserlevel|s:3:"255";serendipityRightPublish|s:1:"1";
And now I try to enter an entry and get logged out:
Code: Select all
http://blog.rince.de/serendipity_admin.php?serendipity[adminModule]=entries&serendipity[adminAction]=new
GET /serendipity_admin.php?serendipity[adminModule]=entries&serendipity[adminAction]=new HTTP/1.1
Host: blog.rince.de
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://blog.rince.de/serendipity_admin.php
Cookie: PHPSESSID=dc2279ad1ad90e3473f5e4ec5e2ce06c; serendipity[karmaVote]=a%3A0%3A%7B%7D
HTTP/1.x 200 OK
Date: Tue, 18 Mar 2008 22:32:42 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch10
X-Powered-By: PHP/5.2.0-8+etch10
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Serendipity-InterfaceLangSource: Content-Negotiation
X-Serendipity-InterfaceLang: de
Content-Length: 4205
Content-Type: text/html; charset=UTF-8
Set-Cookie: serendipity[old_session]=dc2279ad1ad90e3473f5e4ec5e2ce06c; expires=Thu, 17-Apr-2008 22:32:42 GMT; path=/; domain=blog.rince.de
Set-Cookie: serendipity[userDefLang]=de; expires=Thu, 17-Apr-2008 22:32:42 GMT; path=/; domain=blog.rince.de
Via: 1.1 blog.rince.de
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
----------------------------------------------------------
And the Cookie-Content is as followed:
Code: Select all
sudo more /var/lib/php5/sess_dc2279ad1ad90e3473f5e4ec5e2ce06c
SERVER_GENERATED_SID|b:1;no_smarty|N;
(I changed the sensible parts of the second cookie, like username, Password and mailaddress).