palpatin wrote:Sure that's what i meant, by the passwords are sent as plain text.
Sure, just as the entire session is sent plaintext. And mail. And telnet. And irc. And the list goes on.. woo how excitement! </sarcasm>
So even if you cared enough, you would need to sniff the cookie (and spoof the connection as well). But if you can do this, you have better things to do with your time, obviously.