Re: session data vs cookie data
| From: | Michael Kimsal | Date: | Wed, 30 Jan 2002 14:53:03 +0000 |
| Subject: | Re: session data vs cookie data | ||
| References: | 1 | Groups: | php.general php.general |
| Request: | Send a blank email to php-general+get-82752@lists.php.net to get a copy of this message | ||
Jerry Verhoef wrote:
It is possible to "steal" a session because a session_id is usually based on a cookie. So I always store the IP, HTTP_X_FORWARD and USER_AGENT in the session. And check them every page. kind regards, JerryDo you null the user if the IP changes? IPs can change during a user's session, so I wouldn't base the validity of the session solely based on IP. Michael Kimsal