Am 22.04.2012 21:38, schrieb Michael Heydekamp:
>> protecting sessions from hijacking by remember the user-agent
>> > at start and abort each request with the same session ID and
>> > a different user-agent is common sense and some implementations
>> > are also including the client IP
> Didn't know that. But how can a different user on a different machine have
> the same session ID (if not by random)? Is there any way to a) get hold of
> the ID of any other user's session, and b) to take influence on his own
> session ID in a way that he would identify himself with the same ID?

what do you think how long it takes to write a cookie like this?
the only interesting is 

beeing in a open WLAN without ssl and anybody can fake it in seconds

Cookie: mailviewsplitterv=244; mailviewsplitter=262; composesplitterv=175; 
folderviewsplitter=300; addressviewsplitter=250; addressviewsplitterd=200; 

Attachment: signature.asc
Description: OpenPGP digital signature

Roundcube Users mailing list

Reply via email to