Re: Stopping stolen / spoofed / linked sessions

From: Date: Thu, 28 Jun 2001 06:57:05 +0000
Subject: Re: Stopping stolen / spoofed / linked sessions
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-55456@lists.php.net to get a copy of this message
: defeats the purpose of PHP sessions. I can check the HTTP_REFERER to see if : the user came from my own site, but that can be spoofed. I can log and check : the users IP address, but that can't be relied upon. : : Is there any reliable way around this? Am I missing something obvious? On the server where you are storing the session ID, also include her User-Agent and remote IP. Remote IP has some flaws when a proxy cache is involved. User-Agent stays the same fairly much through an entire session. Hopefully they aren't using *exactly* the same browser and IP. Or use one time session tokens that get reissued after each request and then invalidated. Breaks reloads and back functionality. Turu. -- Stephen Cope - http://sdc.org.nz/

« previous php.general (#55456) next »