Re: Stopping stolen / spoofed / linked sessions
| From: | Stephen Cope | Date: | Thu, 28 Jun 2001 06:57:05 +0000 |
| Subject: | Re: Stopping stolen / spoofed / linked sessions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-55456@lists.php.net to get a copy of this message | ||
: defeats the purpose of PHP sessions. I can check the HTTP_REFERER to see if
: the user came from my own site, but that can be spoofed. I can log and check
: the users IP address, but that can't be relied upon.
:
: Is there any reliable way around this? Am I missing something obvious?
On the server where you are storing the session ID, also include her
User-Agent and remote IP.
Remote IP has some flaws when a proxy cache is involved. User-Agent stays
the same fairly much through an entire session.
Hopefully they aren't using *exactly* the same browser and IP.
Or use one time session tokens that get reissued after each request and
then invalidated. Breaks reloads and back functionality.
Turu.
--
Stephen Cope - http://sdc.org.nz/