Re: Re: session security issue

From: Date: Wed, 15 Aug 2001 01:55:22 +0000
Subject: Re: Re: session security issue
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-62726@lists.php.net to get a copy of this message
I guess it is... but read the replys to my email, the solution is quite simple and effective. At 16:49 14/8/2001 +0100, you wrote:
what about registering a var called loggedin with the session and then testing on each script to see if it's set to 1 or something ? then base the access on that ? that's what i use and then register uid with the session as well so you can use it througout your site ... ok you've got me worried now, are there any problems with security doing it that way ???? Steve "Christian Dechery" <cdechery@brfree.com.br> wrote in message news:5.0.0.25.2.20010814084143.027c69e0@pop.brfree.com.br... I have pages that uses session for security that looks something like this: <?php session_start(); if( !isset($uid) ) { include("include/auth.inc.php"); auth_user(); } more code... ?> so $uid tells me if the user is logged on or not... but what if somebody calls the script directly from the address bar like this: http://server/script.php?uid=10 wouldn't this be a security problem? ____________________________ Christian Dechery (lemming) http://www.tanamesa.com.br Gaita-L Owner / Web Developer -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net
____________________________ . Christian Dechery (lemming) . http://www.tanamesa.com.br . Gaita-L Owner / Web Developer

« previous php.general (#62726) next »