RE: [PHP] Protecting from session hijacking
| From: | Jason Murray | Date: | Wed, 04 Jul 2001 09:34:03 +0000 |
| Subject: | RE: [PHP] Protecting from session hijacking | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-56148@lists.php.net to get a copy of this message | ||
> I think a session should be from the same IP all it's life, and this
> should be build into php. Internal networks will be seen as the same
> ip, so session can be stolen by somebody else in the same
> internal net, but not from outside of it.
>
> Now tell me what's wrong with my opinion, b/c it's too simple
> to work :)
Four words: "Load Balancing Proxy Servers".
Jason