Session security
| From: | Stut | Date: | Tue, 29 May 2007 17:04:29 +0000 |
| Subject: | Session security | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-29874@lists.php.net to get a copy of this message | ||
Hi all,
Just wanted to get your opinion on a discussion currently going on on the general list.
Why does the PHP session extension not use something like the user agent to validate that a session ID has not been hijacked? Or is this something that just hasn't been implemented yet?
-Stut