Alex Rivera | Logout

Is it possible to "pirate" a session variable (I do not want to know how)

Asked 2010-08-09T19:56:53.070
10

I am currently doing a website in php, we are using a Session variable to store the permission level of each user.

For example, if any one of you would go on the website, you would automatically get a session variable with a value of "member".

What I am asking is: Is it possible for an attacker to go on the website and modify the value of the session variable for "admin" instead of "member"

I am not asking how, just if it is possible, and if so what kind of special access would the attacker would need (ex: access to the code, ....)

I have an alternative solution, which would be to replace the permission value with a token that would expire over time.

The second solution is way longer to implement.

Thanks for your help!

Edit
Report

1 Answer

3

The higher risk comes from an attacker stealing an active session, you can find about it here:

answered 2010-08-09T20:06:11.930

Your Answer