RE: [PHP-DEV] trans-sid warning?

From: Date: Tue, 20 Aug 2002 02:45:00 +0000
Subject: RE: [PHP-DEV] trans-sid warning?
Groups: php.dev 
Request: Send a blank email to php-dev+get-87121@lists.php.net to get a copy of this message
> Again, this is a good step, but is not at all effective against an > attacker motivated to compromise your site. You are right. However, it could be an acceptable policy to "improve" overall security. > The problem is, while this means something to the developer, it means > nothing to the average end-user, especially since most large ISP users > will have ip's that fluctuate form request-to-request. I agree again. But once again, maybe a strict policy could make a user open a new session when their IP address change (this policy would not be mandatory of course)... This would probably be a pain but could on the other hand give a feeling of increased security to your visitor and discourage a regular attacker imho

« previous php.dev (#87121) next »