Re: Cookies/Remeber password
| From: | Chris Adams | Date: | Wed, 21 Jun 2000 23:06:40 +0000 |
| Subject: | Re: Cookies/Remeber password | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2553@lists.php.net to get a copy of this message | ||
> Does this mean that my cookies from other domains can be copied from the
> web, or just if I let somebody on my machine they can copy my cookies?
Not off of the web usually - there've been a couple nasty bugs that would
let a hostile website get cookies from other domains under certain
circumstances, but they've been patched. One of these days I'm going to
collect stats on browsers with security holes and create a warning module
that could be used to check the current user's user agent so you could give
the user a warning message ("Warning: IE5.0 has a JavaScript vulnerability.
Go to http://windowsupdate.microsoft.com/ to get
the patch").
From your machine, yes. Anything can be retrieved, including things like
saved passwords. If they've got physical access to the box, assume the
worst.