Re: session hijacking
| From: | Chris Shiflett | Date: | Mon, 20 Oct 2003 00:23:29 +0000 |
| Subject: | Re: session hijacking | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166698@lists.php.net to get a copy of this message | ||
--- Ryan A <ryan@coinpass.com> wrote:
> Somehow 1 person has found out about them and is creating havoc with
> that damn account by changing those variables to differient numbers
> ...any idea how he is doing that?
I have many ideas.
First of all, I bet you are using PHP sessions, and you have done nothing
beyond getting them to work, right? One important note about PHP sessions is
that they provide the mechanism only; it is your job to provide whatever
security you deem appropriate. Read the section entitled Sessions and security
here:
http://www.php.net/session
If you have taken steps to prevent impersonation, can you describe them? I'm
sure I can easily evaluate the potential weaknesses in your approach.
Chris
=====
My Blog
http://shiflett.org/
HTTP Developer's Handbook
http://httphandbook.org/
RAMP Training Courses
http://www.nyphp.org/ramp