Use the cookie mechanism to verify whether user logon is vulnerable.
Source: Internet
Author: User
Is there a vulnerability in user login verified using the cookie mechanism? A weak question! If A accesses A website, the website writes the encrypted token to its cookie. when A accesses the website in the future, all tokens in the cookie will be available. in this case, if I put the token in browser A in my browser cookie by some means, do not use the cookie mechanism to verify that user login is vulnerable?
A weak question!
If A accesses A website, the website writes the encrypted token to its cookie. when A accesses the website in the future, all tokens in the cookie will be available. in this case, if I put the token in browser A in my browser cookie by some means, do not forge it into A's identity ???
Are there any vulnerabilities or provide guidance on the correct methods for logon verification? please kindly advise. thank you!
------ Solution --------------------
Let's take a look at the basic truth you are talking about.
Http://bbs.phpchina.com/thread-217757-1-1.html
------ Solution --------------------
The key is how the encryption method is...
------ Solution --------------------
Therefore, cookie spoofing occurs"
------ Solution --------------------
Yes, this is cookie spoofing, so be careful to be intercepted by poor websites.
Qq has a friend's impression function. I have captured packets and analyzed it. its identity authentication also uses cookies. Then I found a friend and copied his qq cookie to simulate a request to evaluate the impression of others. The result is successful. This happened a few years ago. I don't know if it has changed the verification mechanism.
In the past, dvbbs also revealed a simple cookie verification vulnerability. He directly put all the information of each user, including permissions, in the cookie. without encryption, he simply sorted the user ID, password, and permissions in a disordered order. Then, you only need to find the character that identifies the permission and change it to the administrator level. anyone is an administrator.
------ Solution --------------------
Cookie alone is a problem.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service