ds2010630 2016-05-30 21:38
浏览 171
已采纳

如果有人嗅探您加密的cookie数据并将其原样发送到服务器怎么办?

This might be an irrelevant question , but I'm wondering whether this can happen..

In HTTPS cookie data like phpssid transfers as an encrypted big random number.

What if someone sniffs that encrypted random number and send it to the server as it is? So the server decrypt that id and allows the hacker to log in as someone else. Is this possible?

  • 写回答

3条回答 默认 最新

  • dongmian5325 2016-05-30 22:10
    关注

    Yes, exactly. Cookie data if discovered by a third party may be replayed to replicate functionality. Note that you say someone 'sniffs' the cookie over HTTPS, which, if everything is working as it should, would not happen. If you are asking if the encrypted values of SSL/TLS can be replayed to the same effect, no that cannot happen. The plaintext value is needed for this to work.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)
编辑
预览

报告相同问题?

手机看
程序员都在用的中文IT技术交流社区

程序员都在用的中文IT技术交流社区

专业的中文 IT 技术社区,与千万技术人共成长

专业的中文 IT 技术社区,与千万技术人共成长

关注【CSDN】视频号,行业资讯、技术分享精彩不断,直播好礼送不停!

关注【CSDN】视频号,行业资讯、技术分享精彩不断,直播好礼送不停!

客服 返回
顶部