AW: [PHP] Stopping stolen / spoofed / linked sessions
| From: | Bill Rausch | Date: | Fri, 29 Jun 2001 22:43:16 +0000 |
| Subject: | AW: [PHP] Stopping stolen / spoofed / linked sessions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-55646@lists.php.net to get a copy of this message | ||
Sebastian Stadtlich said:
there is an option in php ini :I looked at this thing and can't figure out that it does very much. If someone makes a web page that contains a link to my site that contains the PHPSESSID=... then that session id will be invalid. However, if they just type the same string into their browser by hand, it is accepted? It seems that there is no stopping session spoofing if using the URL method. The only work around is to expire sessions quickly or to require that cookies be used? -- Bill Rausch, Software Development, Unix, Mac, Windows Numerical Applications, Inc. 509-943-0861 bill@numerical.comsession.referer_check =which should fit your needs not sure how to use it, but probably one of the php-developers on this list can assist...