Re: Cookies/Remember password
| From: | Chris Adams | Date: | Wed, 21 Jun 2000 21:51:14 +0000 |
| Subject: | Re: Cookies/Remember password | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2539@lists.php.net to get a copy of this message | ||
> not only can cookies be copied, to my horror i found out they can also be
> changed...
> Sites that use cookies for identity and use some running auto increment ID
> to know
> who the user is instead of a long token are vulnerable...
Yes. It bears repeating that you cannot trust anything received from the
browser.
The best approach is to use a single cookie to identify the browser to the
server and make sure that that value is very, very hard to guess. In almost
all cases, using the PHP4 session library will be safer than building
something yourself.