<?xml version="1.0" encoding="windows-1252"?>
<node id="11246" title="Login and CGI security (&quot;open cookie jar&quot;) problem." created="2000-05-12 05:34:23" updated="2005-08-10 08:51:41">
<type id="1857">
categorized question</type>
<author id="11732">
QandAEditors</author>
<data>
<field name="doctext">
Let's say I login on the browser, and click a few times here and there on the web-server to do stuff. Then, I get distracted and go to a webmail site to retrieve and read my mail without closing the current browser.  One of the messages has a link to an &amp;quot;evil&amp;quot; website, having malicious scripts, etc.  When I click on the link, information about which websites I had visited before, my IP, etc., will be  sent to the &amp;quot;evil&amp;quot; website.  Using that data it's able to do malicious stuff on the server I visited last, since I had already logged on before.  The &amp;quot;evil&amp;quot; website will be able to send commands to the server as me!
&lt;p/&gt;
So, my question is.... How do you, webmasters, solve or prevent this problem?  Is there a better way than prompting the user for their login ID and password everytime they go to restricted area on the web server, or webpage?</field>
<field name="parent_node">
1830</field>
</data>
</node>
