note 34548 deleted from function.setcookie by vincent

From: Date: Wed, 10 Sep 2003 18:48:25 +0000
Subject: note 34548 deleted from function.setcookie by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-55982@lists.php.net to get a copy of this message
Note Submitter: adamh@densi.com ---- Keep in mind for security's sake that cookies can be edited by the client and stolen from the client. Like $_GET and $_POST, Their data should NOT be trusted. Don't put passwords (even hashes), credit card numbers, SQL query parameters, filenames, or anything else sensitive in them! With particular reference to the auth form from lcattani at urbanet dot ch: it should use session variables and not cookies, since session variables are stored on the server and so their data CAN be trusted. The only way for a client to read his session variables besides through your script is with root access to your web server. In this particular script, anybody could copy the username and MD5 password cookies from the browser's computer - the *real* password is not needed.

« previous php.notes (#55982) next »