Re: Session security
| From: | Antony Dovgal | Date: | Tue, 29 May 2007 17:14:32 +0000 |
| Subject: | Re: Session security | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29875@lists.php.net to get a copy of this message | ||
On 29.05.2007 21:04, Stut wrote:
Hi all, Just wanted to get your opinion on a discussion currently going on on the general list. Why does the PHP session extension not use something like the user agent to validate that a session ID has not been hijacked? Or is this something that just hasn't been implemented yet?Please elaborate. -- Wbr, Antony Dovgal