RE: [PHP] Sessions / logins / cookies / security
| From: | John Holmes | Date: | Wed, 17 Jul 2002 01:11:35 +0000 |
| Subject: | RE: [PHP] Sessions / logins / cookies / security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-108001@lists.php.net to get a copy of this message | ||
> So, if there is no uid and pwd in $_SESSION, I check in $_COOKIE. If
> there's nothing there, they aren't logged in as far as I can tell. On
> every
> page I validate the uid and pwd against the database, so the only way
you
> could fake being another user is to know the uid AND md5()'d pwd.
Or steal it. :)
I hope you have checked your site for any cross-site scripting
vulnerabilities. This is exactly where vulnerabilities like this come
into play...
---John Holmes...