Just tested that and that worries me even more... Got the same session-id 
too. Which means that an administrator uses the same session id as a regular 
user does. Doesn't sound too good.

"Michael Vincent van Rantwijk" <[EMAIL PROTECTED]> schreef in bericht 
news:[EMAIL PROTECTED]
> RML wrote:
>> Yes, IE gives me 2 session id's. That what I expected to get on a 
>> multi-tab browser too.
>
> Hm, and what happens when you open two windows, not tabs, in Mozilla 
> Firefox?
>
>> "Michael Vincent van Rantwijk" <[EMAIL PROTECTED]> schreef in bericht 
>> news:[EMAIL PROTECTED]
>>> RML wrote:
>>>> Next question: differs a cookie with individual tab in FireFox?
>>> No, because two tabs are just like two windows and their documents share 
>>> cookies for the same domain. Now the question is, what happens when you 
>>> open two windows in MSIE i.e. do you get two session id's?
>>>
>>>> "Michael Vincent van Rantwijk" <[EMAIL PROTECTED]> schreef in bericht 
>>>> news:[EMAIL PROTECTED]
>>>>
>>>>> Store a session cookie with that session id and check if that cookie 
>>>>> is stored ;)
>>>>>
>>>>> Michael
>> 


_______________________________________________
Mozilla-security mailing list
[email protected]
http://mail.mozilla.org/listinfo/mozilla-security

Reply via email to