From: volker_grabsch@... (Volker Grabsch) Date: 2003-08-18T04:00:17+09:00 Subject: CGI:Session and security Hello Folks, There are some simple standard problems which crowd my brain :-) * creating a session using a hidden field like cgi['sess_id'] instead of a cookie ... or first try the cookie and if it's rejected, go the other way This should be easy to achieve. Either put automatically a hidden field after each