Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Unable to impersonate another user although having its cookie Jul 01 2009 10:14AM
Juan Kinunt (kinunt gmail com)
Hi,

I'm auditing a web application programmed in CakePHP and I'm having a problem.
I'm almost sure the authentication mechanism is carried by a cookie
but I'm unable to impersonate another user using its cookie.
The probe I do is opening two sessions with two different users (one
in internet explor...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus