|
|||||||||||
|
Re: Hijacking URL Encoded Session IDs using Referer Logs
From: zeno <bugtraq(at)cgisecurity.net>
Date: Mon Nov 25 2002 - 10:50:41 EST
A big problem is people hear the buzzword cookie and security and think every website
can steal every cookie from every site they ever visited. This isn't true unless they exploit
some browser flaw. The only risk a cookie has is if it is stolen (*usually* through xss attacks)
Obviously some people will disable cookies. A *better* approach(if no cookies are used)
would be to tie the session (if in url)
Always lots of factors. > server vendors stop allowing URL encoded session IDs by default.
Another reason why a cookie is better to use. > Does hotmail or yahoo use URL session IDs? E-mail someone a link to
Yes I see this maybe once a month or two for people using smaller free webmail companies I simply enter in the referer and boom get in there mailbox.
>
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:44 EDT |
||||||||||
|
|||||||||||