[EMAIL PROTECTED] wrote:
That JSESSIONID are you putting that in the URL or in a cookie. So if you put it in a URL its not
secure and can never be secure and I can hack you with ethereal but if

The session ID in a cookie is equally as vulnerable as in the URL.

C


-- ------------------------------------------------------------------------- Chris Merrill | http://www.webperformanceinc.com Web Performance Inc.

Website Load Testing and Stress Testing Software
-------------------------------------------------------------------------

_______________________________________________
Juglist mailing list
[email protected]
http://trijug.org/mailman/listinfo/juglist_trijug.org

Reply via email to