Page 1 of 1

Links/Cookies with personalized page info

Posted: Tue Jan 03, 2006 4:46 am
by cruzlite
Durring recent review of FAQ section, I realized I am guilty of 'violation' of number 3)...

3) Can I just copy an URL from the IBM web site, and paste it into my post?

Of course you can, but only copy up to the first "?". Otherwise, if you're copying an URL from a page that you got to from your personalized page, you can cause anyone who clicks on the link to set a cookie on their machine with your personalized page info in it.

a) What info would be contained in such a cookie?
b) What are the ramifications...[Does this reresent a security issue...Should links be edited?]

Thanks,
Don

Edit; In retrospect, this post is probably in the wrong category...feel free to move

Posted: Tue Jan 03, 2006 7:02 pm
by GomJabbar
I think what is meant is if you go to a link on IBM's site using your machine info (model/type), a cookie is set on your laptop. The content's of this cookie are reflected in the URL. Now if someone clicks on the IBM link you provided, you will change the cookie on their machine (which reflects their model ThinkPad) to a cookie that reflects your model ThinkPad. As a result, the viewer that clicked on your link will see incorrect (certain model specific) info later, if they visit certain pages on IBM's site.

I don't see how this represents any sort of security threat.

These are just my thoughts on this.

Posted: Tue Jan 03, 2006 7:07 pm
by JaneL
I think that harkens back to when you had a userid and password and a personalized page for your system. I should probably update that.