Re: Re: cvs: pearweb /public_html login.php
| From: | Jim Winstead | Date: | Sat, 23 Nov 2002 00:46:32 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 3 | Groups: | php.pear.cvs |
| Request: | Send a blank email to pear-cvs+get-7542@lists.php.net to get a copy of this message | ||
On Sat, Nov 23, 2002 at 12:37:43AM -0000, Richard Heyes wrote:
> > don't kid yourself, this change isn't any more secure. you're still
> > passing around an easily hijacked token.
>
> Of course it's more secure. Hijack the previous incarnation and the password
> is yours, hijack this however and you still have to crack it.
hijack this incarnation, and all you have to do is set the cookie
yourself. or are there places where the site requires the password even
when the auth cookie is sent? (my assumption was not, based on the code
i saw, but i didn't look beyond the recent patches.)
'any' was a poor choice of word. 'all that much' might have been a
better choice. :)
jim