Protecting from session hijacking
| From: | Arcady Genkin | Date: | Wed, 04 Jul 2001 05:52:19 +0000 |
| Subject: | Protecting from session hijacking | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-56132@lists.php.net to get a copy of this message | ||
Is there any real way to protect against possibility of session
hijacking? I thought of checking IP address on subsequent requests,
but apparently this cannot be relied on because of HTTP proxies etc.
Any wizdom on the matter? (I'm already saving the session files in a
directory protected from unwanted eyes.)
--
Arcady Genkin
i=1; while 1, hilb(i); i=i+1; end