Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Results 1 to 5 of 5
  1. #1
    Join Date
    Apr 2006
    Location
    Leamington Spa
    Posts
    1,375
    Tokens
    72

    Latest Awards:

    Default Sessions and Cookies...

    Right, well, yeah...
    Basically some people are all like "Sessions are the sex. Don't use cookies they're <insertafairlyrudewordhere>".
    What I'm wondering is... What's the actual difference?

    Because I really don't know and some people are like... Well yeah, what I said above, and some people are like "I prefer cookies."
    So explain this to me if you can, I really don't get it.
    i've been here for over 8 years and i don't know why

  2. #2
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Sessions are stored server-side really and cookies are client-side.

    So basically, cookies can be modified which scares some developers.

  3. #3
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    Can you not protect cookies from being edited in any way?

    As vBulletin must use cookies and it isnt exactly insecure.
    Coming and going...
    Highers are getting the better of me

  4. #4
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Cookies are perfectly secure if you use them properly.

    Some people set a cookie with someone's username/password/etc but when they check if the user is logged in or for SQL Queries (which contain the user's account name) in the script they only use the username in the cookie. So if you modified your username cookie you could get other peoples information or go in their account.

    Obviously you can stop people from doing the above by making your script secure. But some people dont (E.G Naresh & his user system).

  5. #5
    Join Date
    Oct 2006
    Location
    Peterborough, UK
    Posts
    3,855
    Tokens
    216

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    Cookies are perfectly secure if you use them properly.

    Some people set a cookie with someone's username/password/etc but when they check if the user is logged in or for SQL Queries (which contain the user's account name) in the script they only use the username in the cookie. So if you modified your username cookie you could get other peoples information or go in their account.

    Obviously you can stop people from doing the above by making your script secure. But some people dont (E.G Naresh & his user system).
    Yeah but Naresh doesn't even add anti spam to his coding so there's about as much use trusting his coding as there is trusting a bum with your credit card and pin.


    Also you can stop it (like vbulletin does) by storing a secured password hash in your cookie, when your script looks at the username, grabs your already encrypted password, then encrypts it again (to get the even more secure one for the cookie) and if they're not the same then you can just kick them out.


    visit my internet web site on the internet
    http://dong.engineer/
    it is just videos by bill wurtz videos you have been warned

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •