Page 3 of 3

Re: Auto Login

Posted: Sun Jan 02, 2011 6:23 pm
by eatcomics
dandymcgee wrote:
eatcomics wrote: I script put on said sight could send said cookie to a specified place for storage and retrieval ;)

and yeah its a security flaw....
In that case the security flaw isn't how cookies work, but rather that the site is allowing arbitrary scripts submitted by a non-trusted user (you) to execute on its behalf. It's called Cross-site scripting (XSS) and is preventable.
Right right right, but you know what I mean :P I was just saying you can get it.... and have temporary access to user's accounts