Re: Session security

From: Date: Tue, 29 May 2007 17:16:50 +0000
Subject: Re: Session security
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-29876@lists.php.net to get a copy of this message
Stut wrote: > Hi all, > > Just wanted to get your opinion on a discussion currently going on on > the general list. > > Why does the PHP session extension not use something like the user agent > to validate that a session ID has not been hijacked? Or is this > something that just hasn't been implemented yet? The user agent is trivial to spoof. If you are going to hijack someone's session, it is very easy to also hijack their user agent string, so I don't see how that solves anything. -Rasmus

« previous php.internals (#29876) next »