Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6109149
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T14:22:22+00:00 2026-05-23T14:22:22+00:00

I read http://www.codinghorror.com/blog/2008/08/protecting-your-cookies-httponly.html Log into a website, copy the essential cookie values, then paste

  • 0

I read http://www.codinghorror.com/blog/2008/08/protecting-your-cookies-httponly.html

Log into a website, copy the essential
cookie values, then paste them into
another browser running on another
computer. That’s all it takes. It’s
quite an eye opener.

My question is, does this method also work if we use php/aspnet sessions.

And if it does work, what techniques can we (as web developers) employ to prevent this trick from working. Basically I do not wish the user to be able to login to his account just by pasting cookies, a password is a MUST.

If the above is not possible, does it mean that even for google products like Gmail, I will have some way to login into my account without requiring my password?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T14:22:23+00:00Added an answer on May 23, 2026 at 2:22 pm

    sessions are sessions – accomplished by storing an ID token in a cookie. YOu cannot prevent the cookies from being manually copied between browsers.

    You can attempt to do things like logging the original User-Agent string when they log in, and compare each time (if they logged in with Firefox, and are suddenly using Opera, hmmMmMmmmmmm). Same for IP addresses… but IP addresses are problematic for mobile users and people behing multi-homed proxy server systems, such as most of AOL and the like. Their IP can potentially change for EVERY request.

    There’s no foolproof method of preventing cookie sharing that can’t be bypassed (change your browser’s UA so they ALL claim to be a single type/version), or produce false-positives (IP changes due to proxies).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I've set up my subversion server following the steps on : http://www.codinghorror.com/blog/2008/04/setting-up-subversion-on-windows.html The server
I've read articles like these: http://www.codinghorror.com/blog/archives/001166.html http://www.databasejournal.com/features/mssql/article.php/3566746/Controlling-Transactions-and-Locks-Part-5-SQL-2005-Snapshots.htm And from what I understand, SQL Server
... after having just read http://www.cocoadev.com/index.pl?CocoaInsecurity ... I am curious to know about your
I am using jqGrid ( http://www.trirand.com/blog/ ) to display some read-only data. The resizeable
I have read the documentation ( http://dev.mysql.com/doc/refman/5.1/en/partitioning.html ), but I would like, in your
Cannot read http://www.earnforex.com/blog/2010/08/forex-technical-analysis-for-week-0809%E2%80%940813/ how to encode the url to be able to read it
I read ( http://www.stereopsis.com/FPU.html ) mentioned in ( What is the fastest way to
I read here http://www.daniweb.com/code/snippet217293.html# it is possible. What should be activated in PHP.Ini or
So, here is the discussion I have just read: http://www.mail-archive.com/delphi@delphi.org.nz/msg02315.html BeginUpdate and EndUpdate is
I read from http://www.apple.com/iphone/specs.html that IPhone4's screen is 960-by-640-pixel resolution at 326 ppi. But

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.