osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Session stealing

This is a discussion on Session stealing within the osCommerce 2.2 Modification Help forums, part of the osCommerce 2.2 Forums category; hello everyone! i have a question, i now use OSCommerce for a couple of days, now my question is if ...


Go Back   osCommerce and osCMax shopping cart software forums > osCommerce 2.2 Forums > osCommerce 2.2 Modification Help

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 02-11-2004, 02:58 PM
Lurker
 
Join Date: Feb 2004
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
claudia
Default Session stealing

hello everyone!

i have a question, i now use OSCommerce for a couple of days, now my question is if i send someone the whole url of the site i am on, for example: product_info.php?products_id=25&osCsid=b53c99e 8ab941c4bf87b0997ac19e885

what if that guys logs in with my account, isn't that a security risk?

sorry my question might be a bit stupid

x0x0x
claudia
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2  
Old 02-11-2004, 04:52 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 10,330
Thanks: 68
Thanked 322 Times in 305 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default

Not stupid. It is a small risk but they would still have to login and to do that they need your username and password to get access to your account, and if the session has already expired there is no risk at all.

But, it would be better to delete the session from the link...
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates. New designs every month!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host.

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
session id in URL cominus osCMax v1.7 Discussion 3 11-11-2004 05:34 PM
Session ID andyy15 osCommerce 2.2 Modification Help 3 08-15-2004 11:40 PM
Session Help doggifts osCommerce 2.2 Modification Help 1 10-21-2003 07:09 PM
SSL Errors, Session Cookie, Session Cache, NOVICE Problems? hanool osCommerce 2.2 Modification Help 1 09-07-2003 11:49 AM
session id thorben osCommerce 2.2 Installation Help 2 06-03-2003 06:35 AM


All times are GMT -8. The time now is 06:13 PM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax