Re: session data vs cookie data

From: Date: Wed, 30 Jan 2002 14:53:03 +0000
Subject: Re: session data vs cookie data
References: 1  Groups: php.general php.general 
Request: Send a blank email to php-general+get-82752@lists.php.net to get a copy of this message
Jerry Verhoef wrote:
It is possible to "steal" a session because a session_id is usually based on a cookie. So I always store the IP, HTTP_X_FORWARD and USER_AGENT in the session. And check them every page. kind regards, Jerry
Do you null the user if the IP changes? IPs can change during a user's session, so I wouldn't base the validity of the session solely based on IP. Michael Kimsal

« previous php.general (#82752) next »