TIP: Click on subject to list as thread! ANSI
echo: aust_avtech
to: Rod Gasson
from: Bob Lawrence
date: 2004-04-01 08:02:18
subject: Locking Windows

RG> Cookies are (in my opinion) a somewhat obsoleted method these
RG> days. Many servers now use "session ID's" in their place. It
RG> acheives pretty much the same purpose, but they aren't quite as
RG> persistant as cookies. The main benefit though is that
RG> sessionID's can't be disabled like cookies can (even though
RG> I've never seen a real need to disable cookies anyway). 

 If I wanted to stuff Splong's computers, I'd give serious
consideration to using a false cookie. It seems to me, to be a perfect
entry point. I know they're text, but they don';t *have* to eb
text, and you and John have already decided that text can be anything
but the 32 control characters (there are easy ways around that too).

 My fear is *any* code given access to my computer - not the cookie
itself; the *access*.

Regards,
Bob

--- BQWK Alpha 0.5
* Origin: Precision Nonsense, Sydney (3:712/610.12)
SEEN-BY: 633/104 260 262 267 270 285 640/296 305 384 531 954 1042 690/734
SEEN-BY: 712/610 848 774/605 800/221 445
@PATH: 712/610 640/531 954 633/260 267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.