note 34548 deleted from function.setcookie by vincent
| From: | vincent@php.net | Date: | Wed, 10 Sep 2003 18:48:25 +0000 |
| Subject: | note 34548 deleted from function.setcookie by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-55982@lists.php.net to get a copy of this message | ||
Note Submitter: adamh@densi.com
----
Keep in mind for security's sake that cookies can be edited by the client and stolen from the
client. Like $_GET and $_POST, Their data should NOT be trusted. Don't put passwords (even
hashes), credit card numbers, SQL query parameters, filenames, or anything else sensitive in them!
With particular reference to the auth form from lcattani at urbanet dot ch: it should use session
variables and not cookies, since session variables are stored on the server and so their data CAN be
trusted. The only way for a client to read his session variables besides through your script is with
root access to your web server. In this particular script, anybody could copy the username and MD5
password cookies from the browser's computer - the *real* password is not needed.