Forms based security without cookies?

From: Stephen Barrett (stephen_barrett@nospam.aoncons.com)
Date: 07/24/02


From: "Stephen Barrett" <stephen_barrett@nospam.aoncons.com>
Date: Wed, 24 Jul 2002 11:58:49 -0400


Is it possible to do forms based security without actually storing cookies
on the client machine? Forms based security looks like a perfect fit for
our application except we have hundreds of users who have cookies disabled
for one reason or another. We authenticate the users using information in a
database, but on machines that have cookies disabled, the site doesn't work.
We aren't using permanent cookies, just temporary ones with a 20minute
timeout.

Is there a way to do what forms based security is doing without the cookie?
If not, what would you recommend my next step be?

TIA



Relevant Pages

  • Re: They can break ZoneAlarm easily !
    ... packet filter firewall or a port mapper or some other additional security. ... outlook express settings are restricted zone, ... Also, I'd try deleting your cookies, and then making sure in your internet ...
    (comp.security.firewalls)
  • Re: IE6 problems with verizon search
    ... Are you running WinXP SP2 or WinXP SP3? ... This step will help us clear cookies, restore the security level back ... Select the General tab, and in the Temporary Internet files window, click ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • [NEWS] Mozilla Cookie Stealing
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Cookies are often used to identify and authenticate users to a website. ... A bug in Mozilla allows an attacker to steal the user's cookies for any ... Mozilla has a bug that lets you bypass this protection and steal cookies ...
    (Securiteam)
  • Re: They can break ZoneAlarm easily !
    ... You have one of the most powerful OS there is with lots of security features ... www.google.com and search on "Securing Outlook Express", "Securing Internet ... > Also, I'd try deleting your cookies, and then making sure in your internet ... > High safety for all other zones. ...
    (comp.security.firewalls)
  • Re: web info re: passport security problems?
    ... Marc Slemko does great job finding vulnerabilities in systems that use ... cookies. ... I believe that XML Web Services security, which allows to use PKI and ... > Robert Nagle, Technical Writer Austin Texas ...
    (microsoft.public.security)