Re: Protecting against Cookie copying

[prev] [thread] [next] [Date index for 2004/11/08]

From: Perrin Harkins
Subject: Re: Protecting against Cookie copying
Date: 21:49 on 08 Nov 2004
On Mon, 2004-11-08 at 09:27, Martin Moss wrote:
> What I wish to do is prevent another user copying the
> session cookie, from one computer to another, and then
> gaining access.

If you're talking about packet sniffing attacks, use SSL and call it a
day.  If you're talking about a technically advanced user who has access
to your site signing in with LWP or similar and then moving the cookie
to another machine, forget it.  There is nothing you can do to prevent
this that won't cause problems for some segment of potential users.

- Perrin


        -- 
        Report problems: http://perl.apache.org/bugs/
Mail list info: http://perl.apache.org/maillist/modperl.html
List etiquette: http://perl.apache.org/maillist/email-etiquette.html

Protecting against Cookie copying
Martin Moss 14:27 on 08 Nov 2004

Re: Protecting against Cookie copying
Rici Lake 15:23 on 08 Nov 2004

Re: Protecting against Cookie copying
Sam Tregar 16:27 on 08 Nov 2004

Re: Protecting against Cookie copying
Martin Moss 16:44 on 08 Nov 2004

Re: Protecting against Cookie copying
Perrin Harkins 21:49 on 08 Nov 2004

Generated at 11:26 on 21 Dec 2004 by mariachi v0.52