Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Unable to impersonate another user although having its cookie Jul 01 2009 02:00PM
pUm (hijacka googlemail com)
just a gues,
but try to fake the user agent. something in the http header must be
part of the cookie auth. so try them all and then reduce. My guess is
that it is the user-agent

2009/7/1 Juan Kinunt <kinunt (at) gmail (dot) com [email concealed]>:
> Hi,
>
> I'm auditing a web application programmed in CakePHP and I'm having a ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus