osCmax v2.5 User Manual
Results 1 to 2 of 2

Session stealing

This is a discussion on Session stealing within the osCommerce 2.2 Modification Help forums, part of the osCommerce 2.2 Forums category; hello everyone! i have a question, i now use OSCommerce for a couple of days, now my question is if ...

      
  1. #1
    Lurker
    Join Date
    Feb 2004
    Posts
    2
    Rep Power
    0


    Default Session stealing

    hello everyone!

    i have a question, i now use OSCommerce for a couple of days, now my question is if i send someone the whole url of the site i am on, for example: product_info.php?products_id=25&osCsid=b53c99e 8ab941c4bf87b0997ac19e885

    what if that guys logs in with my account, isn't that a security risk?

    sorry my question might be a bit stupid

    x0x0x
    claudia

  2. #2
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,907
    Rep Power
    568


    Default

    Not stupid. It is a small risk but they would still have to login and to do that they need your username and password to get access to your account, and if the session has already expired there is no risk at all.

    But, it would be better to delete the session from the link...
    Michael Sasek
    osCMax Developer


    osCmax Installation Service
    - Have our professionals install osCmax on your server - same day service!
    osCmax 2.5 User Manual - the must have beginners guide to osCmax v2.5

    Stay Up To Date with everything osCMax:
    Free osCmax Newsletters - Security notices, New Releases, osCMax News
    osCmax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

Similar Threads

  1. session id in URL
    By cominus in forum osCmax v1.7 Discussion
    Replies: 3
    Last Post: 11-11-2004, 04:34 PM
  2. Session ID
    By andyy15 in forum osCommerce 2.2 Modification Help
    Replies: 3
    Last Post: 08-15-2004, 11:40 PM
  3. Session Help
    By doggifts in forum osCommerce 2.2 Modification Help
    Replies: 1
    Last Post: 10-21-2003, 07:09 PM
  4. SSL Errors, Session Cookie, Session Cache, NOVICE Problems?
    By hanool in forum osCommerce 2.2 Modification Help
    Replies: 1
    Last Post: 09-07-2003, 11:49 AM
  5. session id
    By thorben in forum osCommerce 2.2 Installation Help
    Replies: 2
    Last Post: 06-03-2003, 06:35 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •