|
Posted by Rik on 08/18/06 13:11
Jerry Stuckle wrote:
> Rik wrote:
>> When using GET variables, HTTPS is a must.
>>
>
> And why is that? There's no major difference between GET and POST in
> how the data is sent to the server. And the user could change the GET
> param whether http or https is used.
You're absolutely right, I don't really know what I was thinking, I'm a little
bit off :-). (Offcourse I blame the fever, it couldn't possibly me normal self
making this mistake..:P) Regardless what method is used, if you want to prevent
session hijacking just use https instead of http.
Grtz,
--
Rik Wasmus
Navigation:
[Reply to this message]
|