Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can somebody steal your sessionID and impersonate your browser??

Status
Not open for further replies.

galtulsa

Programmer
Dec 15, 2000
1
US
Can somebody listen the sessionID that the server send to the client as a cookie when a new session is created and use that session ID to impersonate a user while they are browsing the ASP application?

Thanks,
galtulsa.
 
> They have to have interecpted the transmission between you and the server.

Not if they have a trojan horse running on your computer!

-pete
 
I find that hard to believe that it can be possible because all client side session IDs are obviously stored on the clients computer but if you look at the cookie itself part of it is encrypted with server information, if it has been modified it will not work, I heard even if the file itself is updated it will not work at all. I am not sure if this is a rumor though :)

Gordon R. Durgha
gd@vslink.net
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top