Security. If you allow people to post active links to your
app and you render them as usable links. A user could post
a malicious link that could enable them to gain immediate
access to someone else's live session.
They post a link to a file on their own server. This file
retrieves the HTTP_REFERERR value. It will contain
the cookieless session id in the url. Their script notifies
the attacker and provides the link. They click the link
and they are instantly recognized as the original user.
Not good... And, yes it does work.
--
2004 and 2005 Microsoft MVP C#
Robbe Morris
http://www.masterado.net
Earn $$$ money answering .NET Framework
messageboard posts at EggHeadCafe.com.
http://www.eggheadcafe.com/forums/merit.asp