Forum Discussion
flomkrl_29950
Nimbostratus
Nov 27, 2008Cookie steal risk ?
Hello,
If an other user catch the BIGIP cookie, is it able to access to the application without authentification ? , i'm refering to IRULE ClientAuthUsingHTMLForms (http://devcentral.f5.com/wiki/default.aspx/iRules/ClientAuthUsingHTMLForms.html)
Or does the authid include source client ip&port info ?
Thanks for your explanation ,
Regards,
flo
- Hamish
Cirrocumulus
A couple of small observations about cookies... And this iRule. - flomkrl_29950
Nimbostratus
Is there any way to make this cookie secure ? - hoolio
Cirrostratus
If you have clients connecting from behind pools of proxies or that are on DHCP with publich IP addresses, it's possible that their IP address would legitimately change during a session.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects