Re: Protecting from session hijacking

From: Date: Wed, 04 Jul 2001 09:32:33 +0000
Subject: Re: Protecting from session hijacking
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-56147@lists.php.net to get a copy of this message
> hijacking? I thought of checking IP address on subsequent requests, > but apparently this cannot be relied on because of HTTP proxies etc. but isn't better than nothing ? I think a session should be from the same IP all it's life, and this should be build into php. Internal networks will be seen as the same ip, so session can be stolen by somebody else in the same internal net, but not from outside of it. Now tell me what's wrong with my opinion, b/c it's too simple to work :) -- Marius Andreiana

« previous php.general (#56147) next »