Join us at IRC!
Understanding is the answer, hatred is the problem, and hackers are the slaves abused and destroyed in the process of peace online - Deshouleres
Wednesday, May 23, 2012
Navigation
Members Online
Total Online: 43
Web Spiders: 21
Guests Online: 40
Members Online: 3

Registered Members: 70170
Newest Member: bahmx
Latest Articles
View Thread

HellBound Hackers | Computer General | Increasing Security

Author

Can this be done, and how accurate would it be?

Mb0742
Member



Posts: 189
Location:
Joined: 26.11.07
Rank:
Hacker Level 2
Posted on 26-06-08 09:54
I am starting a website and my main desire is to protect my member's as much as I can I have taken the steps to ensure safe cookies, like basing them off the IP of the user. However the site is one where you can purchase items off and when dealing with money you can never be too safe. The problem is that, yes, an IP based of an IP is safe however a person on the same network can still exploit a flaw or what-not then inject the stolen cookies without the IP check doing anything.

So now with my theory - if the cookies are based not only on IP but also on when they were set it would be impossible to inject. So does PHP have a function to check when a cookie was set and if so how accurate is it?

Thanks everyone.


Mb
javascript:alert("hi")
Author

RE: Can this be done, and how accurate would it be?

Uber0n
Member



Posts: 1963
Location: Sweden‭‮
Joined: 13.06.06
Rank:
God
Posted on 26-06-08 10:25
Mb0742 wrote:
The problem is that, yes, an IP based of an IP is safe however a person on the same network can still exploit a flaw or what-not then inject the stolen cookies without the IP check doing anything.

True. Many admins who use IP-based sessions underestimate this risk.

So now with my theory - if the cookies are based not only on IP but also on when they were set it would be impossible to inject. So does PHP have a function to check when a cookie was set and if so how accurate is it?

No idea :right:



http://uber0n.webs.com/
Nope http://uber0n.webs.com/
Author

RE: Can this be done, and how accurate would it be?

Bot H2H
Member



Posts: 14
Location: England, UK
Joined: 13.11.06
Rank:
Apprentice
Posted on 04-07-08 23:26
not really sure what you can do. is it a custom built system made by you or is it a piece of software from a company?


Protecting websites since 2007.
how2hack@hotmail.com samdickie05 http://supportablesystems.info
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 

 

Links
By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2008- 2009. Since 3rd December 2004.