Jump to content

encrypting cookies....


localhost

Recommended Posts

right now on my website, if you have a cookie editor, you can edit the user_name cookie from any username, to any username and act like anyone! I need to know how I can encrypt it so the user won't be able to change it without it messing up the cookie entirely. but I need it so I can decrypt it so I can display the username, unless there is another way?

Please post back.
Link to comment
https://forums.phpfreaks.com/topic/17216-encrypting-cookies/
Share on other sites

You could use a reversable encryption method... That would almost as point less as no encryption though... 

Funny thing is, i discovered my ISP's webmail site had the flaw of encrypting a username in a cookie... But no password so someone could just make a md5 username put it in the right cookie and be in as someone else... Bout 3 days after i figured that out their webmail site changed :D

How does your login script and you script that creates the cookie work?
Link to comment
https://forums.phpfreaks.com/topic/17216-encrypting-cookies/#findComment-72925
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.