NYCPHP Meetup

NYPHP.org

[nycphp-talk] Another stupid thing

Daniel Convissor danielc at analysisandsolutions.com
Sun Feb 1 12:57:43 EST 2009


Michelle:

> I see cookies are viewable and editable.
> 
> Does anyone know if any browsers allow the user to view and edit the request
> Authorization?

Absolutely _everything_ sent to the server can be edited in one way or 
another.  This includes things such as, but not limited to, user agents, 
cookies, auth information, form submissions, request URIs.

--Dan

-- 
 T H E   A N A L Y S I S   A N D   S O L U T I O N S   C O M P A N Y
            data intensive web and database programming
                http://www.AnalysisAndSolutions.com/
 4015 7th Ave #4, Brooklyn NY 11232  v: 718-854-0335 f: 718-854-0409



More information about the talk mailing list