note 37193 added to function.setcookie

From: Date: Thu, 06 Nov 2003 13:49:45 +0000
Subject: note 37193 added to function.setcookie
Groups: php.notes 
Request: Send a blank email to php-notes+get-59988@lists.php.net to get a copy of this message
Variables in cookies are not safer than variables in query string, we can easily send fake cookies even without editing a file <?php function send_cookie($host,$path){ $dati="" ; $fp = fsockopen ($host, 80, $errno, $errstr,30); socket_set_blocking ($fp,1) ; if (!$fp) { echo "$errstr ($errno)<br>\n"; } else{ fputs ($fp, "GET /$path HTTP/1.0\r\nHost: $host\r\n"); fputs($fp,"Cookie:fake1=".urlencode('this is fake')."; fake2=".urlencode('this is fake too').";\r\n\r\n") ; while (!feof($fp)) { $dati.= fgets ($fp,2048); } } fclose ($fp); echo($dati) ; } send_cookie("localhost","info.php") ; ?> This sends a couple of cookies and reads the response ---- Manual Page -- http://www.php.net/manual/en/function.setcookie.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37193 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37193&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37193&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#59988) next »