in reply to Trouble with cookies
Your login implementation is absolutely horrible, to say the least. You do realize that anybody can provide your website with any cookie value he or she wants, right? So, all I have to do is manually send a "loggedIn=true" cookie to this page of yours, and I will have full administration access.
You need to come up with a better 'login' scheme, perhaps using sessions, so that you can verify that the person providing the cookie has the proper permissions to do so. In any case, don't leave it like this, using a simple true/false value to determine who gets administration provileges.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Trouble with cookies
by superfrink (Curate) on Jan 15, 2005 at 03:06 UTC |