RE: [PHP-GENERAL] Session management.
| From: | Kari Asikainen | Date: | Mon, 22 May 2000 09:02:48 +0000 |
| Subject: | RE: [PHP-GENERAL] Session management. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-272@lists.php.net to get a copy of this message | ||
> I am looking for a mechanism that makes the sessions more secure.
> For example a hacker could try a url like mypage.php?PHPSESSID=
> dfc67bcf1d137cf599507b574a7f415c where this session id is
> something random that
> the hacker tries. If the site has several thousand hits per day
> then the hacker
> could get lucky and hit an active session and gain access.
The cracker has "quite many" combinations to try so this won't be a problem
:) And if you are writing an online bank or something else that requires
very high level of security force the user to type his password and check
it's validity from db before doing anything "important" ie. ship an order
etc.
-Kari