WebApp Sec mailing list archives

Re: Encrypted URL


From: Fred van Engen <fred.van.engen () xbn nl>
Date: Mon, 2 Feb 2004 17:31:40 +0100

On Mon, Feb 02, 2004 at 10:43:08AM -0500, Dean Saxe wrote:
We have this problem with our apps.  It appears that MSIE, depending on how
its installed, will sometimes share session cookies between browsers,
causing what you describe below.  Other times it will not share those
session cookies, effectively allowing multiple browser windows to access a
single app and differentiate between them.


IE shares cookies between browser windows in the same process. I.e. if
you open a new window with Ctrl-N from an existing window, you share
cookies. If you open a new browser window from your Windows task bar or
Start menu, you don't share cookies. HTTP login credentials work the
same.


Unfortunately, this appears to be an option at installation and I don't know
if it can be changed on the fly through registry settings or preferences.
If it can be changed it would save me a lot of headaches with end users and
QA. ;-)


I recall that there used to be a browser option forcing the use of an
existing process for new windows, even when you opened them from outside
a running IE process. Can't find it in IE6 though.


Regards,

Fred.

-- 
Fred van Engen                              XB Networks B.V.
email: fred.van.engen () xbn nl                Televisieweg 2
tel: +31 36 5462400                         1322 AC  Almere
fax: +31 36 5462424                         The Netherlands


Current thread: