Re: Stopping stolen / spoofed / linked sessions

From: Date: Sat, 30 Jun 2001 22:20:07 +0000
Subject: Re: Stopping stolen / spoofed / linked sessions
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-55692@lists.php.net to get a copy of this message
> > Ok, stop right there. Sessions and authentication have nothing to do with > > each other. To create a secure authenticated site you should be using > > HTTP-based authentication over SSL. Sessions are simply for maintaining > > state across http requests and have nothing to do with authentication. > > > > -Rasmus > > So setting a 'loggedin' session variable once a person has authenticated, and > checking for that session variable each request before proceeding is not ok? No, this is what I was trying to make sure people realized. It is only ok if this happens over SSL and there is no chance that someone else can sniff the session id. -Rasmus

« previous php.general (#55692) next »