Shiflett->Re: [PHP] session hijacking

From: Date: Mon, 20 Oct 2003 00:42:44 +0000
Subject: Shiflett->Re: [PHP] session hijacking
Groups: php.general 
Request: Send a blank email to php-general+get-166704@lists.php.net to get a copy of this message
Hi, Thanks for replying. > First of all, I bet you are using PHP sessions, and you have done nothing > beyond getting them to work, right? One important note about PHP sessions is > that they provide the mechanism only; it is your job to provide whatever > security you deem appropriate. Yep, I just created the session and nothing beyond. Am new to PHP and first time/project user with sessions. now what to do? According to the (link that you sent me) docs this is the only one that seems a bit feasible: session.use_only_cookies I cant have ssl as its a shared webhosting and i dont have my own IP. Globals have to be on as a lot of programs are dependant on them. session.use_trans_sid is set to 1 What do you suggest? Thanks, -Ryan

« previous php.general (#166704) next »