Re: Session management.
| From: | Ben Peter | Date: | Wed, 14 Jun 2000 06:18:00 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1815@lists.php.net to get a copy of this message | ||
On Wed, 14 Jun 2000, Kelly Barrett wrote:
>
> You could also check that the referer (environment variable HTTP_REFERER)
> was from one of your own pages (by the domain) on every page where a session
> should be valid, and kick them out if it doesn't checkout.
>
> Cheers,
> Kelly.
>
That wouldn't do as the REFERER is sent by the client and thus, in a brute
force attack you could just send a wrong HTTP_REFERER in the Header of
your request.
Ben
--
Benjamin Peter
Zentropy Partners GmbH
ph. +49-69-96244-395
pax +49-69-96244-244
http://www.zentropypartners.com
"Integrate the building and marketing of digital businesses"