    I&#039;m trying to lessen the burden on the database on my site ( ) by using cookies to store the user&#039;s username & other info while on the site instead of checking a querystring (containing userid and password) against the database on every page.<BR><BR>Now what exactly would prevent a knowledgeable visitor from going into the cookie text file and changing his userid to someone else&#039;s? Even if I store a password there and compare it against a password being passed constantly through a querystring, if he changes both instances of the password, he&#039;ll effectively be someone else, since his info is only checked against the database when he first logs in.<BR><BR>Is there a more secure way of using cookies than this? How do other sites do it?<BR>

    saskia laroo

    you could encrypt the info that you&#039;re putting into the cookie and decrypt it when you pull it out

    Why not do this:<BR><BR>on your default page check for session loggedon var if false then check for cookie info if have some then hit db up to match userid & password from db. If match set session var to loggedon. If no cookie value then ask for userid and password, save if check against db ok and user requests save info, set session logged on ok also. On each page check session loggedon if true then ok else redirect to default page?

    Jason

    Krank is absolutely correct. By the way, i would start using method="post" instead of querystring. If you need any help with coding the sessions and cookies, just ask. I have a quick template i can show ya.<BR><BR>

