Posted by Chung Leong on 11/16/06 20:51
Erwin Moller wrote:
> The name of the file reflects the sessionid.
> So both are comprimised...
But if there are other variables in the cookies, they won't be
compromised. That's the point I was getting at.
> I don't get that Cheong, what goes excactly wrong with JS in combination
> with trans_sid? I use btoh a lot, so I am curious what you mean.
Let me clarify. I mean when you have URLs generated through Javascript,
then these won't be transparently handled.
[Back to original message]
|