session hijacking

From: Date: Mon, 20 Oct 2003 00:09:42 +0000
Subject: session hijacking
Groups: php.general 
Request: Send a blank email to php-general+get-166694@lists.php.net to get a copy of this message
Hi, We have a site that runs a kind of membership section. When a person logs in we have his username + 3 variables in session, the 3 variables are used for background processing and are never disclosed to the client, all 3 variables contain 1 or 2 digit numbers. Somehow 1 person has found out about them and is creating havoc with that damn account by changing those variables to differient numbers...any idea how he is doing that? We can ask him to stop but that does not solve the problem.... how can we stop him by making changes on our server or what to do? Please HEAAAAAALP (help) Cheers, -Ryan

« previous php.general (#166694) next »