Dumb session / cookie / password questions

From: Date: Wed, 10 Jul 2002 20:09:53 +0000
Subject: Dumb session / cookie / password questions
Groups: php.general 
Request: Send a blank email to php-general+get-106940@lists.php.net to get a copy of this message
I am a little confused about storing stuff in cookies/sessions and how to prevent spoofing of them. A user logs in, his e-mail address or user id and password(md5'ed) is checked against my database. Assuming it matches, I then set a cookie with the users id + email. What is to stop someone from spoofing that cookie? I obviously don't want to put the password in a cookie .. can someone point me in the direction of an article about this? I've searched around, but I'm not finding stuff about in a preventing spoofing / security aspect. Thanks, Chad

« previous php.general (#106940) next »