ssl security question
| From: | Jan Grafström | Date: | Sat, 08 Jun 2002 08:37:57 +0000 |
| Subject: | ssl security question | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-101258@lists.php.net to get a copy of this message | ||
I have made a file wich start a session and set a session variable if user
and pass are verifyed.
Than I use the session variable to protect all other userfiles.
To run the file I enter:
http://myserver.com/start.php3?user=xxxxx&pass=yyyyyy
What is the differans using SSL and enter the same url?
If a hacker sniff the ssl-string can he send that string and start the file
anyway?
--
Regards,
Jan Grafström
Sweden