Quote:
Originally Posted by SirAdrian
People can steal your cookie information, then load it into their browser and be logged in as you. They can also post harmful content (movies, images, etc). If they were to post <base> tags or iframes, they can muck up all your links or load other sites in your pages.
Javascript is probably the biggest concern, but there many other annoyances.
|
Stealing the cookie information and logging in as another user (especially an admin) is the only item that really scares me, I'm not concerned about the others. How difficult is it for someone to do that? I don't need details (I don't want anyone that doesn't already know how to do it to learn), but I'd like to know if this is something that can be done by anyone with decent computer skills, or if it's something that is possible only by an NSA level hacker. I'm not concerned with the latter.