Re: Session security
| From: | Rasmus Lerdorf | Date: | Tue, 29 May 2007 17:16:50 +0000 |
| Subject: | Re: Session security | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29876@lists.php.net to get a copy of this message | ||
Stut wrote:
> Hi all,
>
> Just wanted to get your opinion on a discussion currently going on on
> the general list.
>
> Why does the PHP session extension not use something like the user agent
> to validate that a session ID has not been hijacked? Or is this
> something that just hasn't been implemented yet?
The user agent is trivial to spoof. If you are going to hijack
someone's session, it is very easy to also hijack their user agent
string, so I don't see how that solves anything.
-Rasmus