Stolen session token (possible in nextcloud)

This script was intended to only show session-cookies that are still alive.
You can see all registred logins when you change the querry a little bit.
I have changed the script so that you can choose on startup if you only want to see the logins with session cookies or all registred logins.
When they are listed, does not mean, that those users are realy loged in. Therefore it is ordered by last activity.

Update it with this command:

[Edit]: … new home of the nc-who script is here:


you should do that in the mysql console yourself on your own risk.
If you are not that good in SQL-commandline, than you can do it in phpMyAdmin and delete the sessions you want to delete from there.

1 Like