User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Database Design section within the Web Development category of DaniWeb, a massive community of 360,994 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 2,489 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Database Design advertiser:
Views: 7046 | Replies: 5
Reply
Join Date: Jan 2004
Location: new yawk
Posts: 38
Reputation: Dominick is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Dominick's Avatar
Dominick Dominick is offline Offline
Light Poster

cookie spoofing

  #1  
Jan 28th, 2004
Is it easy or even possible for a user to create a cookie on his own and use it on a site that uses authentication with cookies?
Dominick@tech-lounge.com
www.tech-lounge.com
www.v-dommi.net
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Jan 2004
Location: Ireland
Posts: 61
Reputation: Redshift is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Redshift Redshift is offline Offline
Junior Poster in Training

Re: cookie spoofing

  #2  
Jan 28th, 2004
Generally, the authentication Info is hashed within the cookie so in order to make a cookie you would need the password amongst other things for the account which generated it. Generally attacks using cookies are executed by using stolen cookies.
Reply With Quote  
Join Date: Jan 2004
Location: new yawk
Posts: 38
Reputation: Dominick is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Dominick's Avatar
Dominick Dominick is offline Offline
Light Poster

Re: cookie spoofing

  #3  
Jan 28th, 2004
easy enough. thanks for the quick reply
Dominick@tech-lounge.com
www.tech-lounge.com
www.v-dommi.net
Reply With Quote  
Join Date: Jan 2004
Location: Netherlands
Posts: 152
Reputation: floris has a spectacular aura about floris has a spectacular aura about 
Rep Power: 6
Solved Threads: 2
floris's Avatar
floris floris is offline Offline
vBulletin.com Staff

Re: cookie spoofing

  #4  
Mar 1st, 2004
It depends on the poorly written code, but it is quite possible to spoof cookies and even steal them remotely using xss
Reply With Quote  
Join Date: Apr 2006
Posts: 1
Reputation: sowiebinich is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
sowiebinich sowiebinich is offline Offline
Newbie Poster

Re: cookie spoofing

  #5  
Apr 4th, 2006
Originally Posted by Redshift
Generally, the authentication Info is hashed within the cookie so in order to make a cookie you would need the password amongst other things for the account which generated it. Generally attacks using cookies are executed by using stolen cookies.

Ok, supposing I have all the cookies I need for cookie authentication, and I'm trying to run some php scripts on one site that will read in other php-generated pages. The problem I'm getting is that the site I'm grabbing from is not recognizing their own cookies or something. I have the required cookies set on my computer for that site, and I have identical ones set on the site I'm trying to run my script on. Do I have to be trying to do this from a server, or at least a computer than can run php?

Ideas?
Reply With Quote  
Join Date: Feb 2005
Posts: 354
Reputation: DanceInstructor is an unknown quantity at this point 
Rep Power: 4
Solved Threads: 12
DanceInstructor's Avatar
DanceInstructor DanceInstructor is offline Offline
Posting Whiz

Re: cookie spoofing

  #6  
Apr 5th, 2006
Are you using curl? You really should have started a new topic in the PHP forum.
Clear Mind Hosting and Web Design

If I've helped you please consider adding to my reputation.
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

DaniWeb Database Design Marketplace
Thread Tools Display Modes

Similar Threads
Other Threads in the Database Design Forum

All times are GMT -4. The time now is 6:34 pm.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC