RE: [PHP] Re: [PHP-DEV] cookies and sessions security
| From: | Jason Murray | Date: | Mon, 15 Jan 2001 22:18:25 +0000 |
| Subject: | RE: [PHP] Re: [PHP-DEV] cookies and sessions security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-34703@lists.php.net to get a copy of this message | ||
> >Very good: keep the thing on a secure connection all the time, set a
> >session id cookie and keep all user info (possibly including
> >remote ip) in the server's session db... (vulnerable to nothing I can
> think of at the moment...)
>
> Wow, I never thought of using the remote IP! Thanks for the tip. I
> am going to use it today for an authentication system I'm building.
Careful. This will die in the butt if the client comes in from an ISP
using load-balancing proxy servers.
Jason
--
Jason Murray
jasonm@melbourneit.com.au
Web Design Team, Melbourne IT
Fetch the comfy chair!