4 ms·
There are sites that make use of sessions without forcing you into using an account. These are also vulnerable.
by gregmuellegger 16y ago
There are sites that make use of sessions without forcing you into using an account. These are also vulnerable.
- bigiain 16y agoWell, sometimes for strange values of "vulnerable". Some of my sites use Apache::Session over non secured http connections, which makes them technically "vulnerable". The only practical thing an attacker can do with those session ids though, is to mess with some custom visitor tracking in my management backend. So perhaps my information about whether a particular inquiry visited my terms and conditions page or my privacy policy page will be wrong. I can live with that.