Back to startpage CookieSecurity


Explanation

Scenario

You want to get access to a password protected area of a website. Usually you have to provide your credentials and if they are right you gain access.

In this case you should put yourself in the role of an attacker who has no valid credentials but wants to access the protected area.

It is your task to get access.

For testing what happens when you got valid credentials you can use the user "guest" with password "guest".

Information: To do this exercise cookies have to be enabled in your browser. In MS Internet Explorer you can enable cookies in the Menu>Tools>Internet Options in the section "Privacy". In Mozilla Firefox you can enable cookies in the Menu>Tools>Configurations.


Login with data stored in a cookie
Username
Password
Show/hide source

Login with only a session-id stored in a cookie
Username
Password
Show/hide source
< Previous page Next page >




Copyright © 2006 SAP AG. All rights reserved.
Legal Notice