Crash1hd
06-09-2003, 10:17 AM
I was wondering now try and keep up with me the simple part is how secure is Session Security??
Heres my thought say you have a website that uses login & password blah blah blah and when you have succesfully logged in it tells your browser that you have a usersession=2 ok so when you goto the members page which checks to see if the browser has the usersession=2 or not and if it does it lets you in!
Ok so I was wondering say I decieded to use my own IIS to create an asp page that gives me usersession=2 and then I goto the members page of that site I have usersession=2 so does the website in question give me access or not???
Basically is there a unique string of code that goes with that usersession=2 that is unique to the website or not???
:cool: just curious if anyone has any Idea!
Heres my thought say you have a website that uses login & password blah blah blah and when you have succesfully logged in it tells your browser that you have a usersession=2 ok so when you goto the members page which checks to see if the browser has the usersession=2 or not and if it does it lets you in!
Ok so I was wondering say I decieded to use my own IIS to create an asp page that gives me usersession=2 and then I goto the members page of that site I have usersession=2 so does the website in question give me access or not???
Basically is there a unique string of code that goes with that usersession=2 that is unique to the website or not???
:cool: just curious if anyone has any Idea!