4 ms·
The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.
by kristinn 14y ago
The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.
- jervisfm 14y agoI don't understand what you are saying ? Is it that there is a security issue arising from the DNS hijacking ? If so what's the issue ?
- deizel 14y agoSay you set a session cookie that spans multiple subdomains (cookie domain = `.example.com`). Now, if one of your authenticated users visits the wrong subdomain, they are directed to a server of name.com's choice. That server now has access to your user's session ID (using Javascript or PHP or whatever to read the cookie).
- drucken 14y agoinvulnerable? You mean "vulnerable", right?
- kristinn 14y agoYeah, I meant vulnerable. My bad. :-) Thanks for the correction.