Re: PHP authenticating and session management

From: Date: Fri, 22 Jun 2001 16:46:58 +0000
Subject: Re: PHP authenticating and session management
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-54905@lists.php.net to get a copy of this message
I have a Q. will the Session ID be stolen by hacker when the ID tranfer bewteen client and server ? Then can the hacker send the ID to server and veiw the user's page ? "Jason Stechschulte" <jpstech@unoh.edu> ????? news:20010622071330.A17903@unwosrv3.unoh.edu... > On Fri, Jun 22, 2001 at 08:59:54AM +0430, Arash Dejkam wrote: > > simply check $username and bring up the user's page ? but this makes it > > possible for any hacker to send a cookie with username and see that page. I > > know that PHP stores a unique random number for each session but how can I > > check that it matches with the number in the cookie. > > > Why not just check for username this way: > > <?php > if(session_is_registered("username")) { > // Do stuff > } > ?> > > Then username has to be registered as a session variable so any hacker > (sic) can't just send a username to see that page. > > -- > Jason Stechschulte > jpstech@unoh.edu > -- > echo "Your stdio isn't very std." > -- Larry Wall in Configure from the perl distribution > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#54905) next »