Re: Session management.

From: Date: Wed, 14 Jun 2000 06:18:00 +0000
Subject: Re: Session management.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-1815@lists.php.net to get a copy of this message
On Wed, 14 Jun 2000, Kelly Barrett wrote: > > You could also check that the referer (environment variable HTTP_REFERER) > was from one of your own pages (by the domain) on every page where a session > should be valid, and kick them out if it doesn't checkout. > > Cheers, > Kelly. > That wouldn't do as the REFERER is sent by the client and thus, in a brute force attack you could just send a wrong HTTP_REFERER in the Header of your request. Ben -- Benjamin Peter Zentropy Partners GmbH ph. +49-69-96244-395 pax +49-69-96244-244 http://www.zentropypartners.com "Integrate the building and marketing of digital businesses"

« previous php.general (#1815) next »