<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="Session fixation - Page 7 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=Session_fixation&amp;p=6">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Session_fixation&amp;p=8">3.Next</a>
</p>
<p>his site<br/>
# A visit to <code><nowiki>evil.example.com</nowiki></code> sets a session cookie with the domain <code><nowiki>.example.com</nowiki></code> on Alice's browser<br/>
# When Alice visits <code><nowiki>www.example.com</nowiki></code> this cookie will be sent with the request and Alice will have the session specified by Mallory's cookie.<br/>
# If Alice now logs on, Mallory can use her account.</p>

<p>When this attack is complete, Mallory can gain access to <code>www.example.com</code> as Alice.</p>

<p>It is not essential that a user</p><p>
<a accesskey="1" href="page.php?w=Session_fixation&amp;p=6">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Session_fixation&amp;p=8">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
