I've recently become aware that Xenforo fourms, at least in their default configuration, are vulnerable to session hijacking attacks. One can steal a cookie from a fourm user (via malicious javascript that the attacker hosts) and use that cookie to authenticate with the fourm. Cookies last 30 days, Xenforo 2FA does not stop this.
Are there any methods for dealing with this? Can I make Xenforo force email confirmation to login when the users IP differs, even when they already have a cookie?
Are there any methods for dealing with this? Can I make Xenforo force email confirmation to login when the users IP differs, even when they already have a cookie?