| 
	
 | 
 Posted by julianmlp on 05/28/06 00:54 
Janwillem Borleffs wrote: 
> julianmlp@gmail.com wrote: 
> > I think through this kind of procedure is hard to hijack an user 
> > session. 
> > What do you think? 
> > 
> 
> You can test this yourself by faking the HTTP request send to the server 
> from another machine using a valid session ID. 
 
Well, I already tried it, and it doesn't work at all. I mean, only 
pasting the url in the browser's address bar of another computer, the 
user can't authenticate, beacause the cookie isn't there, so in some 
way I could say that it is working well. 
 
What I was wondering is: Is there any (simple/easy) way to hijack a 
cookie remotely? (to be afraid of)
 
  
Navigation:
[Reply to this message] 
 |