Cookies can store other information as well. "Other information" may be as harmless as a user name that your favorite website remembers so you don't have it type it in every time you login. It can also be non-trivial like an account number, shopping cart total, social security number and any other personal information. I wish this wasn't the case, but I'm sure there are some websites that do this. The problem does not stop here. Anyone can edit a cookie and change their shopping cart total. Who wouldn't want to buy a brand new TV for a hundred bucks? Wouldn't you also get the store warranty that they always try to sell you but no one buys?
How to edit cookies? Download and install Add N Edit Cookies (a Firefox Add-on).
There are a number of ways to protect yourselves from this vulnerability.
- Do not save sensitive information in cookies.
- Try to utilize server side sessions where possible.
- Encrypt your cookie data.
- Set an expiration that makes sense.
This is one of the best articles I read online. No crap, just useful information. Very well presented. Check following link too it might be useful for you.
ReplyDeletehttp://mindstick.com/Blog/123/What%20is%20Cookie%20poisoning
This comment has been removed by the author.
ReplyDeletealert('XSS')
ReplyDeletebm671 on running schuhe,keensandalsuk,mizuno zapatillas,gymshark suomi,asics outlet,onrunningcloud,gymshark sale,keds buty,onrunningshoesnz if254
ReplyDelete