[mod-security-users] processing a cookie
Brought to you by:
victorhora,
zimmerletw
|
From: joe b. <joe...@ya...> - 2006-04-13 02:10:44
|
Hello list In my debug log I see this. I know this is being created by my php session control. This seems to pass right through my mod_security rules untouched. Raw cookie header "PHPSESSID=57afe9ec2e03d155efde2b7d53171a7e" Adding cookie "PHPSESSID"="57afe9ec2e03d155efde2b7d53171a7e" I want to have rules to check cookie name and that the argument PHPSESSID is there and that the content is (which looks like md5) valid with nothing inserted. I do not have enough knowledge to even begin writing a rule or even to begin formulating how to ask intelligent question about processing cookies. I need your help please. --------------------------------- How low will we go? Check out Yahoo! Messengers low PC-to-Phone call rates. |