note 37193 added to function.setcookie
| From: | fabiostt at libero dot it | Date: | Thu, 06 Nov 2003 13:49:45 +0000 |
| Subject: | note 37193 added to function.setcookie | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-59988@lists.php.net to get a copy of this message | ||
Variables in cookies are not safer than variables in query string, we can easily send fake cookies
even without editing a file
<?php
function send_cookie($host,$path){
$dati="" ;
$fp = fsockopen ($host, 80, $errno, $errstr,30);
socket_set_blocking ($fp,1) ;
if (!$fp) {
echo "$errstr ($errno)<br>\n";
}
else{
fputs ($fp, "GET /$path HTTP/1.0\r\nHost: $host\r\n");
fputs($fp,"Cookie:fake1=".urlencode('this is fake').";
fake2=".urlencode('this is fake too').";\r\n\r\n") ;
while (!feof($fp)) {
$dati.= fgets ($fp,2048);
}
}
fclose ($fp);
echo($dati) ;
}
send_cookie("localhost","info.php") ;
?>
This sends a couple of cookies and reads the response
----
Manual Page -- http://www.php.net/manual/en/function.setcookie.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37193
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37193&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37193&report=yes
Search -- http://master.php.net/manage/user-notes.php