Re: session hijacking

From: Date: Mon, 20 Oct 2003 00:23:29 +0000
Subject: Re: session hijacking
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-166698@lists.php.net to get a copy of this message
--- Ryan A <ryan@coinpass.com> wrote: > Somehow 1 person has found out about them and is creating havoc with > that damn account by changing those variables to differient numbers > ...any idea how he is doing that? I have many ideas. First of all, I bet you are using PHP sessions, and you have done nothing beyond getting them to work, right? One important note about PHP sessions is that they provide the mechanism only; it is your job to provide whatever security you deem appropriate. Read the section entitled Sessions and security here: http://www.php.net/session If you have taken steps to prevent impersonation, can you describe them? I'm sure I can easily evaluate the potential weaknesses in your approach. Chris ===== My Blog http://shiflett.org/ HTTP Developer's Handbook http://httphandbook.org/ RAMP Training Courses http://www.nyphp.org/ramp

« previous php.general (#166698) next »