> The cflogin cookie values are just a base 64 encoding of the
> username and password values you enter into the cfloginuser tag.
>
> I think it's fair to say that's pretty weak.

Well ok then, that's pretty crappy. I don't see why they wouldn't just
generate some GUID sort of thing anyway, and just match that up with data in
memory.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
phone: 202-797-5496
fax: 202-797-5444
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings] [Donations and Support]

Reply via email to