Re: trans-sid warning?

From: Date: Tue, 20 Aug 2002 13:18:32 +0000
Subject: Re: trans-sid warning?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-87151@lists.php.net to get a copy of this message
Sascha:
    If you want your site to be safe, enable
    session.use_only_cookies and be done with it.  No amount of
    checking on the server side can otherwise prevent this class
    of attacks.
By the way, does session.use_only_cookies work with session.use_cookies=off? I'm using an alternative method (HTTP Basic Authentication) for the session id propagation, and would like to prevent users from setting the sid in get/post parameters. mk

« previous php.dev (#87151) next »