Re: Patch to minimize Session Fixation Risks
| From: | Stefan Esser | Date: | Wed, 07 Apr 2004 14:20:32 +0000 |
| Subject: | Re: Patch to minimize Session Fixation Risks | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-8960@lists.php.net to get a copy of this message | ||
Hello,
sure the current user IS the session creator. It is based on client IP addresses. A legal user can have multiple IP addresses at the same time. This can have several reasons...for example a) ISP did disconnect him inbetween clicks b) he is using a proxy but for the https part of your site he has no proxy c) he or is proxy is using a NAT gateway Stefan Esser