Re: cok->Re: [PHP] Re: Session hijacking
| From: | DvDmanDT | Date: | Mon, 20 Oct 2003 00:47:40 +0000 |
| Subject: | Re: cok->Re: [PHP] Re: Session hijacking | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166706@lists.php.net to get a copy of this message | ||
$_REQUEST is a great superglobal, check it out...
And at the top of the hijacked script:
while(list($tmp1,$tmp2)=each($_SESSION))
$$tmp1=$tmp2;
$tmp1=tmp2=NULL;
Could work.. :p
--
// DvDmanDT
MSN: dvdmandt@hotmail.com
Mail: dvdmandt@telia.com
"Ryan A" <ryan@coinpass.com> skrev i meddelandet
news:003201c396a2$e732f290$f081aa51@l2zcaxu7emppqh...
> Hey,
>
> > Use an ini_set in your sessions script (I am assuming that you are using
a
> > seperate script to manage your sessions)
>
> Not really, I use authenticate for the login, then above each script i
have
> a session_start() throughout the site.
> Its gotten to be a habit that i start a script with session_start() then
> continue writing.
>
> > you might start looking for replacements for those
> > scripts as it takes time to make the changes, but it has been a year
since
> > register_globals were turned off by default and mentioned that they were
> > going away in the future.
>
> Ok, something to think about, I guess as i get some time I'll have to sit
> down and make those changes.
>
> > In addition, take a look at some of the other suggestions that were
made,
> > beyond this one.
>
> Yep, lots of brainy guys here.
>
> Thanks for replying.
>
> Cheers,
> -Ryan