Re: PHP authenticating and session management
| From: | Bass??? | Date: | Fri, 22 Jun 2001 16:46:58 +0000 |
| Subject: | Re: PHP authenticating and session management | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-54905@lists.php.net to get a copy of this message | ||
I have a Q.
will the Session ID be stolen by hacker when the ID tranfer bewteen client
and server ?
Then can the hacker send the ID to server and veiw the user's page ?
"Jason Stechschulte" <jpstech@unoh.edu> ?????
news:20010622071330.A17903@unwosrv3.unoh.edu...
> On Fri, Jun 22, 2001 at 08:59:54AM +0430, Arash Dejkam wrote:
> > simply check $username and bring up the user's page ? but this makes it
> > possible for any hacker to send a cookie with username and see that
page. I
> > know that PHP stores a unique random number for each session but how can
I
> > check that it matches with the number in the cookie.
>
>
> Why not just check for username this way:
>
> <?php
> if(session_is_registered("username")) {
> // Do stuff
> }
> ?>
>
> Then username has to be registered as a session variable so any hacker
> (sic) can't just send a username to see that page.
>
> --
> Jason Stechschulte
> jpstech@unoh.edu
> --
> echo "Your stdio isn't very std."
> -- Larry Wall in Configure from the perl distribution
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>