Re: Session hijacking
| From: | Chris Shiflett | Date: | Mon, 20 Oct 2003 02:34:37 +0000 |
| Subject: | Re: Session hijacking | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166724@lists.php.net to get a copy of this message | ||
--- "John W. Holmes" <holmes072000@charter.net> wrote:
> > Either way, what if a bad guy visits this URL:
> >
> > http://www.example.org/foo.php?PHPSESSID=12345
>
> Called session fixation. Here's good paper on this and how to deal
> with it.
>
> http://www.acros.si/papers/session_fixation.pdf
Actually, I didn't mean to reference session fixation (my example used an
existing session). However, this is another important topic; thanks for the
link.
Chris
=====
My Blog
http://shiflett.org/
HTTP Developer's Handbook
http://httphandbook.org/
RAMP Training Courses
http://www.nyphp.org/ramp