Re: SESSION Security
| From: | Ilia A. | Date: | Wed, 14 Aug 2002 23:27:42 +0000 |
| Subject: | Re: SESSION Security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-112618@lists.php.net to get a copy of this message | ||
If a person 'somehow' gains read access to the directory where the sessions
are stored on your server, then yes it is possible for them to get the
session id.
Ilia
On August 14, 2002 06:41 pm, Sascha Braun wrote:
> Is it possible that someone from outside can read the session stored
> on my webserver for getting unencrypted password and usernames?
>
> Schura