I don't mean to make it sound one way or another. I'm just reporting something a user of my forum told me. Since the user seems to be wrong, this thread can be closed. Sorry for the hassle.
I've recently become aware that Xenforo fourms, at least in their default configuration, are vulnerable to session hijacking attacks. One can steal a cookie from a fourm user (via malicious javascript that the attacker hosts) and use that cookie to authenticate with the fourm. Cookies last 30...