Web applications attacks/Cookie injection

From aldeid
Jump to navigation Jump to search

Description

The majority of web applications are based on an authentication mechanism that enables to define user privileges. This mechanism is based on sessions. It defines cookies which validity period depends on the parameters. If the controls are only based on these cookies, the application is likely to be vulnerable, since cookies are saved on local machines. Hence, it is easy to modify their values or manually create new cookies.

Example

Protection

Tools

Comments

Talk:Web applications attacks/Cookie injection