Shiflett->Re: [PHP] session hijacking
| From: | Ryan A | Date: | Mon, 20 Oct 2003 00:42:44 +0000 |
| Subject: | Shiflett->Re: [PHP] session hijacking | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-166704@lists.php.net to get a copy of this message | ||
Hi,
Thanks for replying.
> First of all, I bet you are using PHP sessions, and you have done nothing
> beyond getting them to work, right? One important note about PHP sessions
is
> that they provide the mechanism only; it is your job to provide whatever
> security you deem appropriate.
Yep, I just created the session and nothing beyond. Am new to PHP and first
time/project user with sessions.
now what to do?
According to the (link that you sent me) docs this is the only one that
seems a bit feasible: session.use_only_cookies
I cant have ssl as its a shared webhosting and i dont have my own IP.
Globals have to be on as a lot of programs are dependant on them.
session.use_trans_sid is set to 1
What do you suggest?
Thanks,
-Ryan