Re: SESSION Security

From: Date: Wed, 14 Aug 2002 23:27:42 +0000
Subject: Re: SESSION Security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-112618@lists.php.net to get a copy of this message
If a person 'somehow' gains read access to the directory where the sessions are stored on your server, then yes it is possible for them to get the session id. Ilia On August 14, 2002 06:41 pm, Sascha Braun wrote: > Is it possible that someone from outside can read the session stored > on my webserver for getting unencrypted password and usernames? > > Schura

« previous php.general (#112618) next »