note 73819 deleted from function.setcookie by danbrown

From: Date: Sun, 17 May 2009 17:52:12 +0000
Subject: note 73819 deleted from function.setcookie by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-155034@lists.php.net to get a copy of this message
Note Submitter: mbowie at NOSPAM dot buzmo dot com ---- It would seem that set_cookie will still set a cookie via HTTP, even if the secure parameter is true. So even if your site uses HTTPS/SSL to communicate sensitive data, if the initial cookie was set by set_cookie via HTTP, an attacker listening on the wire could easily spoof a visitor's cookie and gain access to their session. See: http://bugs.php.net/bug.php?id=40778

« previous php.notes (#155034) next »