note 27689 added to ref.session
| From: | thebitman at attbi dot com | Date: | Mon, 16 Dec 2002 06:01:15 +0000 |
| Subject: | note 27689 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-40943@lists.php.net to get a copy of this message | ||
The easiest (and therefor, most vulnerable) method of validating a session is to just keep a copy of
the REMOTE_IP in $_SESSION, and compare it at the beginning of your script. Of course this doesnt
prevent someone from blindly sending things to your server and getting no reply, but I think it will
do a pretty good job of preventing someone from hijacking your session in order to get ahold of an
order confirmation page that has your address and CC# on it.
As a general rule: Keep track of your users. NEVER allow POST data for things like online purchases
without making sure that the last page they were on is the page that should be making that POST (and
I dont mean checking the referer: header. This kind of thing is what the _SESSION variable can be
good for storing)
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+27689
http://master.php.net/manage/user-notes.php?action=delete+27689
http://master.php.net/manage/user-notes.php?action=reject+27689