Re: sessions and security

From: Date: Wed, 27 Dec 2000 12:22:01 +0000
Subject: Re: sessions and security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-31952@lists.php.net to get a copy of this message
On Wed, 27 Dec 2000, K.Simon wrote: > To avoid this you could use javascript. Put in there an exit console > destroing the session if the user closes the browser. Users can easily disable javascipt, and this won't work on some browsers properly. What I am really worried is if a user is accessing through a proxy, whether someone with full access to the proxy can do something by using the URL and hence the session ID, even with SSL (if not using cookies). Anuradha

« previous php.general (#31952) next »