Re[2]: [PHP-DEV] [PROPOSAL] defense against session takeovers

From: Date: Fri, 01 Feb 2002 23:04:21 +0000
Subject: Re[2]: [PHP-DEV] [PROPOSAL] defense against session takeovers
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-78827@lists.php.net to get a copy of this message
> But unfortunately a dedicated server does not cost much more than virtual
> hosting anymore (just have a look at http://powerraq.com/ ).
> PHP is
> mostly pre-installed (with "dev settings" and not "production settings" -
> many admins even forget to switch on safe_mode) and this lazyness
> leads to thousands of insecure PHP installations on production
> machines.

Why would you switch on safe_mode if you have a dedicated server?  That
makes no sense.  There is also nothing unsafe about the session code if
you are on a dedicated server.

-Rasmus



Thread (20 messages)

« previous php.dev (#78827) next »