Dumb session / cookie / password questions
| From: | Chad Day | Date: | Wed, 10 Jul 2002 20:09:53 +0000 |
| Subject: | Dumb session / cookie / password questions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-106940@lists.php.net to get a copy of this message | ||
I am a little confused about storing stuff in cookies/sessions and how to
prevent spoofing of them.
A user logs in, his e-mail address or user id and password(md5'ed) is
checked against my database.
Assuming it matches, I then set a cookie with the users id + email.
What is to stop someone from spoofing that cookie? I obviously don't want
to put the password in a cookie .. can someone point me in the direction of
an article about this? I've searched around, but I'm not finding stuff
about in a preventing spoofing / security aspect.
Thanks,
Chad