RE: [PHP] Sessions / logins / cookies / security

From: Date: Wed, 17 Jul 2002 01:11:35 +0000
Subject: RE: [PHP] Sessions / logins / cookies / security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-108001@lists.php.net to get a copy of this message
> So, if there is no uid and pwd in $_SESSION, I check in $_COOKIE. If > there's nothing there, they aren't logged in as far as I can tell. On > every > page I validate the uid and pwd against the database, so the only way you > could fake being another user is to know the uid AND md5()'d pwd. Or steal it. :) I hope you have checked your site for any cross-site scripting vulnerabilities. This is exactly where vulnerabilities like this come into play... ---John Holmes...

« previous php.general (#108001) next »