Re: [PROPOSAL] defense against session takeovers
| From: | Ivan Ristic | Date: | Sat, 02 Feb 2002 13:17:29 +0000 |
| Subject: | Re: [PROPOSAL] defense against session takeovers | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-78897@lists.php.net to get a copy of this message | ||
> This will secure the default configuration and yet make things
> work for people who want to use sessions over several domains.
But I admit that this improvement can be seen as meaningless
since any user on a shared server can write a script to list
all sessions in a directory and then read all files. This
can be cured only by using the proper PHP engine configuration.
Therefore, let us document this and leave it as is.
--
Ivan Ristic, ivan.ristic@iname.com
[ Weblog on PHP, Software development, Intranets,
and Knowledge Management: http://www.webkreator.com ]