This might be an irrelevant question , but I'm wondering whether this can happen..
In HTTPS cookie data like phpssid
transfers as an encrypted big random number.
What if someone sniffs that encrypted random number and send it to the server as it is? So the server decrypt that id and allows the hacker to log in as someone else. Is this possible?