Re: sessions and security
| From: | Anuradha Ratnaweera | Date: | Wed, 27 Dec 2000 12:22:01 +0000 |
| Subject: | Re: sessions and security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-31952@lists.php.net to get a copy of this message | ||
On Wed, 27 Dec 2000, K.Simon wrote:
> To avoid this you could use javascript. Put in there an exit console
> destroing the session if the user closes the browser.
Users can easily disable javascipt, and this won't work on some browsers
properly.
What I am really worried is if a user is accessing through a proxy,
whether someone with full access to the proxy can do something by using
the URL and hence the session ID, even with SSL (if not using cookies).
Anuradha