Re: PHP authenticating and session management

From: Date: Sat, 23 Jun 2001 00:59:01 +0000
Subject: Re: PHP authenticating and session management
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-54944@lists.php.net to get a copy of this message
Bass??? pressed the little lettered thingies in this order... > I have a Q. > will the Session ID be stolen by hacker when the ID tranfer bewteen client > and server ? Then can the hacker send the ID to server and veiw the user's > page ? > Yes. That *can* happen to any non-encrypted transmission that passes over an untrusted network. It would be difficult to do, so it's unlikely, but it *can* happen. It would require a packet sniffer on your network, on the target network or somewhere between. If you want to prevent this, you should match session ID with requesting IP addresss, log both into a database and check both for each page request. If the data being accessed is *that* important that a hacker would go through that much trouble to hijack a session, you probably should consider using SSL. Christopher Ostmo a.k.a. tech@AppIdeas.com AppIdeas.com Meeting cutting edge dynamic web site needs For a good time, http://www.AppIdeas.com/

« previous php.general (#54944) next »