RE: [PHP] session security issue

From: Date: Tue, 14 Aug 2001 21:32:03 +0000
Subject: RE: [PHP] session security issue
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-62707@lists.php.net to get a copy of this message
Sean, That is a very interesting suggestion. How would you call that using PHP? Thanks, David Price -----Original Message----- From: smccarthy@mercurio.ulpgc.es [mailto:smccarthy@mercurio.ulpgc.es]On Behalf Of Sean C. McCarthy Sent: Tuesday, August 14, 2001 6:12 AM To: Christian Dechery Cc: php-general@lists.php.net Subject: Re: [PHP] session security issue Hi, For security use SSL and get the SSLSession ID instead. This cannot be fooled since it is based in PK handshake and with simetric encryption. Sean C. McCarthy SCI, S.L. (www.sci-spain.com) Christian Dechery wrote: > > I have pages that uses session for security that looks something like this: > > <?php > session_start(); > > if( !isset($uid) ) > { > include("include/auth.inc.php"); > auth_user(); > } > > more code... > ?> > > so $uid tells me if the user is logged on or not... > > but what if somebody calls the script directly from the address bar like > this: http://server/script.php?uid=10 > > wouldn't this be a security problem? > ____________________________ > . Christian Dechery (lemming) > . http://www.tanamesa.com.br > . Gaita-L Owner / Web Developer > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#62707) next »