Re: Re: cvs: pearweb /public_html login.php

From: Date: Sat, 23 Nov 2002 00:46:32 +0000
Subject: Re: Re: cvs: pearweb /public_html login.php
References: 1 2 3  Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-7542@lists.php.net to get a copy of this message
On Sat, Nov 23, 2002 at 12:37:43AM -0000, Richard Heyes wrote: > > don't kid yourself, this change isn't any more secure. you're still > > passing around an easily hijacked token. > > Of course it's more secure. Hijack the previous incarnation and the password > is yours, hijack this however and you still have to crack it. hijack this incarnation, and all you have to do is set the cookie yourself. or are there places where the site requires the password even when the auth cookie is sent? (my assumption was not, based on the code i saw, but i didn't look beyond the recent patches.) 'any' was a poor choice of word. 'all that much' might have been a better choice. :) jim

« previous php.pear.cvs (#7542) next »