Page 1 of 1

phpsessid

Posted: Tue Aug 19, 2003 12:52 am
by avij
Testing various PHPSESSIDs for censorship:

PHPSESSID
PHPSESSID=
&PHPSESSID
&PHPSESSID=
?-
?command=test&-

test1

test2

http://www.test/test.php?-

http://www.test/test.php?command=test&P ... 2345abcdef

Posted: Tue Aug 19, 2003 5:29 pm
by micro
aaa&-
ccc&-ddd
eee&PHPSESSID=
&-
&PHPSESSID=

Posted: Thu Aug 28, 2003 5:04 pm
by Petri6
nothing anymore.

Posted: Thu Aug 28, 2003 9:45 pm
by BogPoet

Posted: Thu Aug 28, 2003 10:10 pm
by avij
BogPoet wrote:Seems to work ;)
Yes, but it's still suggested that people don't post phpsessid's because a) they're still ugly and b) the ids can still be abused if someone wants. The censorship only helps to prevent accidental logins to someone else's account. I think you know this, but not everybody does..

Posted: Thu Aug 28, 2003 10:24 pm
by BogPoet
avij wrote:
BogPoet wrote:Seems to work ;)
Yes, but it's still suggested that people don't post phpsessid's because a) they're still ugly and b) the ids can still be abused if someone wants. The censorship only helps to prevent accidental logins to someone else's account. I think you know this, but not everybody does..
Yes, I know, I just wanted to test it out. That's why the part with the Session ID number is fake (not pointing anywhere).

Posted: Sat Jan 03, 2004 7:11 pm
by avij

Posted: Sat Jan 03, 2004 7:18 pm
by Ganymede

Posted: Sun Apr 25, 2004 10:22 pm
by avij