WebApp Sec mailing list archives

Re: IE cookie menagment and CSRF


From: lazy <lazy () gwsh gda pl>
Date: Sat, 21 Aug 2004 10:12:55 +0200

Dnia 2004-08-21 06:01, Użytkownik Saqib.N.Ali () seagate com napisał:
I think I.E. by default DOES NOT allow modifying 3rd party cookie (i.e cookies from other sites).
i don't need to modify it i just use it to perform an action as authorized user on 3rd party site only GET requests
But you can check this setting on your browser by going in to I.E. -> Tools -> Internet Options -> Privacy (TAB) -> Advance (Button)
doesn't change anything IE sends them anyway

--
Lazy



Current thread: